Purpose of this notice

At Layer 7 we are committed to protecting and respecting your privacy, and to being transparent about how we look after your personal data. This notice explains when and why we collect personal information about people who visit our website, enquire about our services, or work with us; how we use that data; the circumstances in which we may share it; and how we keep it secure.

Our privacy practices are in line with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. Layer 7 Ltd is the data controller for the personal data described in this notice.

Our services evolve, so we may change this notice from time to time. Please check this page to ensure you are happy with any changes. By using our website you agree to this notice. Any questions about it or our privacy practices should be sent to hello@layer7.uk.

How we collect information about you

We obtain information about you when you use our website, enquire about or engage our services, or contact us in any way (email, telephone, or social media). In particular, we may collect data when you:

  • use the site, including limited data about how you browse it;
  • email us or otherwise enquire about our services;
  • engage us to deliver services, or correspond with us during a project;
  • sign up to receive updates or other communications from us;
  • communicate with us by telephone, email or otherwise.

We may also receive information from third parties, such as our hosting and security providers, and combine it with the information you give us. We also use non-personal and anonymised information that does not identify any individual.

What data we process

Information you give us may include:

  • contact and identity details such as your name, organisation, job role, email address and telephone number;
  • the content of your enquiry or correspondence with us;
  • information relevant to scoping and delivering services to your organisation.

We do not collect or store payment card details through this website.

Information collected through your use of the site may include:

  • technical information such as your IP address, time zone setting, device, browser type and version, and operating system;
  • information about your visit, such as the pages and resources you view, page response times and errors, and how you arrived at and left the site.

Cookies

This website does not set any cookies, and we do not use advertising or cross-site tracking. Please see our Cookie Policy for full detail on cookies and log files.

How we use your data, and our lawful basis

  • To respond to your enquiry and take steps to enter into a contract with you, on the basis of our legitimate interests in answering enquiries, and to take pre-contract steps at your request.
  • To deliver, administer and support our services where you engage us, to perform our contract with you.
  • To send you updates or marketing about our services that may interest you, where you have consented, or where we have a legitimate interest in contacting you as a business contact. You can opt out at any time.
  • To operate, troubleshoot, secure, analyse and improve our website and services, on the basis of our legitimate interests.
  • To prevent fraud and misuse, and to keep our business records: on the basis of our legitimate interests and to meet legal obligations.
  • To comply with legal and regulatory obligations: where the law requires it.

Any of these functions may be carried out by us or by trusted third parties, who must process personal data in line with this notice.

Who we share information with

We will not sell or rent your personal information. We share it only where necessary to run our business and deliver our services, with carefully selected providers under contracts that require them to keep it secure and use it only as we instruct. These may include:

  • GitHub (GitHub Pages): our website hosting and content delivery network;
  • Microsoft 365: our email and productivity platform, used to receive and respond to enquiries.

Where data is processed outside the UK, we ensure appropriate safeguards are in place. We may disclose personal data where required by law, to comply with legal process, or to prevent and detect fraud and protect our rights and property. If we sell or restructure our business, personal data may be transferred to the prospective buyer or successor organisation.

How we communicate with you

We send two kinds of email: service messages needed to respond to you and deliver our services, and optional updates or marketing about our services. We will only send marketing where you have consented or where it is permitted for business contacts. You can opt out at any time by using the unsubscribe link in any marketing email or by emailing hello@layer7.uk.

Your rights and choices

Under UK data protection law you have rights over your personal data, including:

  • The right to be informed: through this notice.
  • The right of access: you can ask for a copy of the personal information we hold about you (a Subject Access Request).
  • The right to rectification: to have inaccurate or incomplete data corrected. If your details change, or anything we hold is wrong, email hello@layer7.uk.
  • The right to erasure: to ask us to delete the data we hold about you, where we have no legal reason to keep it.
  • The right to restrict or object to processing: including where we rely on legitimate interests, and to stop direct marketing at any time.
  • The right to data portability.

To exercise any of these rights, contact hello@layer7.uk. We will do our best to comply where we are legally able to.

How long we keep your information

We keep personal data only for as long as necessary for the purposes set out above and to meet our legal obligations, in line with our retention policy, after which it is securely deleted or anonymised. If you would like us to delete your data sooner, and we have no legal requirement to keep it, please email hello@layer7.uk.

Complaints

If you wish to raise a concern about how we have handled your personal data, please contact us first at hello@layer7.uk so we can investigate and put things right. You also have the right to complain to the Information Commissioner's Office (ICO): by phone on 0303 123 1113, or via ico.org.uk.

Keeping your information safe

We take appropriate technical and organisational measures to protect your personal data. Information submitted through this website is transmitted over an encrypted (HTTPS/TLS) connection. No transmission over the internet can be guaranteed to be completely secure, so while we work hard to protect your information we cannot guarantee the security of data you send us, and you do so at your own risk. Where you hold a password for any part of our services, you are responsible for keeping it confidential.

Links to other websites

Our website may contain links to other websites operated by other organisations. This notice applies only to our website, so we encourage you to read the privacy notices of any other sites you visit. We are not responsible for the privacy practices of third-party sites, including any site you may have followed a link from to reach ours.