Legal

Privacy Notice

Last updated: June 2026

This privacy notice covers the Landed Lab platform and website. It explains the personal data we collect from when you engage with us, why we collect it, what we do with it, and what your rights are.

Who are we?

Landed Lab is operated by Orum Consulting Ltd, registered in England and Wales.

Data Controller: Orum Consulting Ltd

Contact: info@landedlab.com

Registered address: Belmont Suite, Paragon Business Park, Chorley New Road, Horwich, Bolton, BL6 6HG.

We are registered as a Data Controller with the Information Commissioner's Office (ICO, the UK's regulator for data protection).

When we refer to data protection law, which laws are we referring to?

  • UK General Data Protection Regulation (UK GDPR)
  • Data Protection Act 2018(DPA 2018)

References to both laws include updates and amendments implemented by the Data (Use and Access) Act 2025 (DUAA), including provisions in force from 5 February 2026 and 19 June 2026.

What are your rights under data protection law?

You have a number of rights relating to the processing of your personal data. If you would like to use any of them, or have any questions, please contact us at info@landedlab.com. We cannot charge you for exercising your rights, although we may make a reasonable charge in the case of frequent, repeat, or unfounded requests. You should expect us to respond within one calendar month. If we anticipate it taking longer, we will let you know and explain why.

Your specific rights are:

  • Awareness: You have the right to be fully informed about why and how we process your personal data. This privacy notice is intended to meet that requirement. If we obtain your personal data from a third party (such as a social media or recruitment platform), we will tell you the source.
  • Access: You have the right to a copy of the personal data we hold about you. It will help us manage your request if you can give us as much detail as possible about what you are looking for and why.
  • Rectification: If you think some of the personal data we hold about you is wrong, you have the right to ask us to correct it.
  • Erasure: You have the right to ask us to delete personal data we hold about you. Where we are holding personal data to fulfil a contract, we will need to retain it in accordance with the retention periods set out in Schedule 2.
  • Restriction: You have the right to ask us to restrict the processing of personal data while we check its accuracy, if you think the processing is unlawful, if you believe we no longer need to process it but you need us to retain it for pending legal claims, or when you are objecting to our legitimate interests processing and we are assessing that objection.
  • Object: Where we process your personal data on the basis of our legitimate interests, you have the right to object. If your objection is valid, for instance in the case of direct marketing, we will stop processing for that purpose.
  • Portability: You can request a copy of your personal data in a machine-readable digital format, which you can then provide to another service, where we are processing your personal data under contract or with your consent.
  • Automated decisions and profiling: You have the right, in certain circumstances, not to be subject to decisions made solely by automated processing (including profiling) if it has a significant legal or similar effect on you. This does not apply where the processing is necessary to fulfil a contract with you, or where you have given us your consent. We do not currently make automated decisions about you.
  • Complaints: You have the right to make a complaint to us as Data Controller (DPA 2018 section 164A, as inserted by section 103 of the Data (Use and Access) Act 2025) if you consider that there is an infringement of the UK GDPR in connection with personal data relating to you. Please see the How to make a complaint section below for full details. You also retain the right to escalate your complaint to the ICO at any time: ico.org.uk | 0303 123 1113.

The rest of this privacy notice covers our processing activities where we act as Data Controller.

We ensure we only process your personal data where it is necessary to deliver our services, manage our business, communicate with you, or for similar reasons you would expect. We collect the minimum amount of personal data needed to properly fulfil the purpose of processing.

Where does your personal data come from?

We receive personal data from you when you:

  • Visit the Landed Lab website.
  • Sign up to our waitlist.
  • Create an account on the platform.
  • Use the platform tocomplete assessments and receive feedback.
  • Interact with us via email or social media.
  • Subscribe to newsletters or marketing communications.
  • Enquire about our services.

Lawful bases for processing

A full list of the personal data we use, and the lawful basis for each purpose, can be found in Schedule 1.

Where we rely on your consent you are free to withdraw it at any time by contacting us at info@landedlab.com or updating your preferences in your account settings. Withdrawing consent does not affect the lawfulness of any processing we carried out before you withdrew it.

Where we rely on legitimate interests you are free to object at any time. We will tell you whether we agree with your objection or, if we do not, explain why.

In the case of direct marketing, we will stop sending communications if you object to our legitimate interests or withdraw your consent, for example by unsubscribing from our newsletter.

Special category personal data

There are additional rules we must follow if we collect certain more sensitive types of personal data, known as special category personal data. These include details of your ethnicity, health, disability, beliefs, and sexuality.

We may collect optional demographic information (such as ethnicity or disability status) from platform users who choose to provide it, solely for the purposes of improving the fairness and equity of our assessment design. We will only do this with your explicit consent, and you may withdraw that consent at any time. We will not use special category data for any other purpose, and we will never make it a condition of using the platform.

How long do we keep your personal data?

Each purpose we identify for using your personal data has its own retention period. Full details are set out in Schedule 2.

Where we are relying on legitimate interests or your consent, we will keep your personal data until you object (and we agree with your objection), or until you withdraw your consent.

Who do we share your personal data with?

We will share your personal data if we receive a legitimate request from a law enforcement agency.

When you submit personal data via our website or platform, that data is processed by the third-party providers who host and support our services. If we communicate with you via email, your data is processed by our email service providers.

Occasionally we may share personal data when seeking professional advice from lawyers, accountants, or business advisors. We will always have a legitimate reason for doing so.

We will never sell your personal data to third parties, and we will never share it for advertising purposes without your explicit consent.

Full details of the organisations we share personal data with, and our relationship with each, are set out in Schedule 3.

International transfers

Some of our third-party software providers operate outside the UK. Where personal data is transferred to countries not recognised as providing an adequate level of data protection, we ensure appropriate safeguards are in place, including:

  • Standard Contractual Clauses (SCCs) as approved by the ICO
  • Binding Corporate Rules, where applicable
  • Additional technical and organisational safeguards

International transfers are governed by the UK GDPR, the DPA 2018, and the DUAA, including any updated transfer mechanisms. We keep our safeguards under review as ICO guidance develops.

How we keep your personal data secure?

  • All personal data transmitted between your browser and our website or platform is encrypted in transit (TLS)
  • Where personal data is stored by our platform and third-party providers, we ensure that encryption at rest is applied
  • Access to personal data is role-based: only those with a legitimate need can access it
  • Systems are password-protected and multi-factor authentication is enabled where available
  • We ensure that appropriate DPAs are in place with all suppliers who process personal data on our behalf, requiring them to apply appropriate security measures and handle international transfers correctly
  • We apply data protection by design and by default across the platform, in accordance with the UK GDPR and DUAA requirements
  • We carry out regular reviews of our security policies, technical measures, and processor arrangements

For full details of where personal data is stored and how it is secured, please see Schedule 3.

Children

Landed Lab is designed for early-career professionals aged 18 and over. We do not knowingly collect personal data from anyone under the age of 18..

In line with the children's higher protection duties introduced by the DUAA (in force from 5 February 2026), we apply data protection by design with specific regard to the possibility of younger users accessing the platform. If we become aware that we have inadvertently collected personal data from someone under 18, we will delete it promptly.

Cookies

For a full list of the cookies we use and how we use them, please see our Cookie Notice on the Landed Lab platform.

In line with updated ICO guidance and the DUAA, certain low-risk functional cookies (such as those used to maintain your login session or to collect aggregate, anonymised analytics) may be set without prior consent. Where cookies involve the processing of personal data beyond this, we will ask for your consent before setting them.

How to make a complaint

If you have a concern about how we have handled your personal data, we encourage you to raise it with us directly in the first instance. Under section 164A of the DPA 2018, inserted by section 103 of the DUAA, you have a statutory right to bring a data protection complaint directly to us as Data Controller.

You can contact us by:

  • Email: info@landedlab.com
  • Post: Orum Consulting Ltd, Belmont Suite, Paragon Business Park, Chorley New Road, Horwich, Bolton, BL6 6HG.

We will acknowledge receipt of your complaint within 30 days and aim to provide a full response without undue delay. We will keep a record of your complaint, the steps taken during our investigation, and the outcome.

If you are not satisfied with our response, or if we have not responded within a reasonable time, you have the right to escalate your complaint to the ICO:

  • Website: ico.org.uk
  • Helpline: 0303 123 1113

Changes to this privacy notice

We may update this privacy notice from time to time to reflect changes to our services, our software providers, or the applicable law. The most current version will always be available on the Landed Lab website. Where changes are material, we will notify you by email or via the platform.

Schedule 1 - Purposes

  • Waitlist/prospective users: name and email address from website sign-up (Website sign-up form) to confirm waitlist registration and send launch updates (consent).
  • Registered users: account details such as name, email address, encrypted password, employment status, graduation year, and career stage (Account registration) for account creation and management (contract).
  • Platform usage data: assessment responses across the five behavioural dimensions, progress data, and feedback (Platform activity) to deliver daily practice and personalised expert feedback (contract).
  • Technical data: IP address, browser type, device information, session and usage logs (Automatic collection on platform use) for security, performance, and aggregate analytics to improve the service(legitimate interests).
  • Optional demographic data: ethnicity, disability status, or similar when voluntarily provided (User-submitted) to improve fairness and equity of assessment design (explicit consent).
  • Marketing/newsletter subscribers: name and email address (Subscription opt-in on website or platform) for product updates, newsletters and launch communications (consent).
  • Financial/transaction records: name, email address, and payment reference (no card data held by us) by the payment processor for invoicing, accounting, and tax compliance (legal obligation/contract).

Schedule 2 - Retention schedule

  • Registered account data: For account management and service delivery. Retained for 3 years from last active use; then deleted from platform database and associated systems.
  • Assessment responses and feedback: For delivering personalised development insights. Retained for 3 years from last active use, or sooner upon account deletion request; then deleted from platform database.
  • Waitlist data for non-converting users: For launch communications. Retained for 12 months from sign-up or until unsubscribe; then deleted from email platform and CRM.
  • Marketing/newsletter data: For sending product updates and communications. Retained until unsubscribe or consent withdrawn. Email retained on suppression list to prevent future unwanted contact; then deleted from email platform; suppression list maintained
  • Technical and usage logs: For security and performance monitoring. Retained for 12 months with automated deletion by hosting provider; then automated deletion by hosting provider
  • Optional demographic data: For assessment design and equity research. Retained until consent withdrawal or account deletion; then deleted immediately upon withdrawl of consent.
  • Financial records: For invoicing, accounting, and tax compliance. Retained for 6 years (HMRC requirement); then deleted from accounting software and hard copies shredded.

Schedule 3 - Third-party processors

The table below lists the organisations we share personal data with, the data shared, their location, their role, and the safeguards in place.

  • Vercel Inc. (USA): IP addresses, usage/session data, platform performance data. vercel.com/legal/dpa
  • Supabase Inc. (USA/AWS): user account data, assessment responses, and platform database content. supabase.com/legal/dpa
  • Microsoft Azure / Microsoft Ireland Operations Ltd (EU/Ireland): platform data where Azure services are used. microsoft.com/licensing/docs/view/Microsoft-Products-and-Services-Data-Protection-Addendum-DPA
  • Squarespace Inc. (USA): IP addresses, usage data, and contact form submissions. squarespace.com/privacy/dpa
  • IONOS SE (Germany/EU): email addresses and communications data. ionos.co.uk/terms-gtc/terms-privacy/
  • Brevo (Sendinblue SAS) (France/EU): names and email addresses for marketing and transactional emails. brevo.com/legal/termsofuse/#dpa
  • Vercel Analytics (USA): aggregate anonymised usage data. vercel.com/legal/dpa
  • GitHub Inc. (USA): source code hosting (personal data only if present in code). github.com/customer-terms/github-data-protection-agreement
  • Anthropic (Claude API, where AI feedback features are used) (USA): assessment responses processed to generate expert feedback, anonymised where possible. anthropic.com/legal/data-processing-addendum
  • Slack Technologies LLC (USA): internal communications, with user data only when required in support contexts. slack.com/intl/en-gb/terms-of-service/data-processing
  • ngrok Inc. (USA): temporary connection data during development and Slack authentication.ngrok.com/dpa