Legal
Privacy Policy
Last updated 29 July 2026
This policy explains what personal data we collect at LEAK, why we collect it, how we use it, and the rights you have over it. It applies to leak-studio.com and to anyone who books a Leak Audit, becomes a customer, or gets in touch.
We aim for plain English. If anything here is unclear, email hello@leak-studio.comand we'll explain.
1. Who we are
LEAK Studio ("LEAK", "we", "us") is the data controller for the personal data described here.
- Trading name: LEAK Studio
- Registered company: [COMPANY NAME LTD] (company number: TBC)
- Registered address: TBC · United Kingdom
- VAT number: TBC
- ICO registration: [ICO REGISTRATION NUMBER]
- Privacy contact: hello@leak-studio.com
2. What we collect
When you use the Leak Calculator
The calculator runs entirely in your browser. If you submit the audit form we store a snapshot of what you entered (missed calls, booking rate, job value, admin hours, hourly cost) so the audit conversation starts with your numbers rather than blank fields.
When you book a Leak Audit
- Your name and business name
- Email address and phone number
- Trade / sector
- The calculator snapshot above, if you completed it
- The time you submitted, the page you submitted from, and your IP address (used only for spam/rate-limit protection)
When you become a customer
- Contact details (name, business, email, phone, address)
- Details of the services you use and the systems we're integrating with (booking, CRM, phone answering, etc.)
- Contracts you sign — including the name you type as a signature, the time you signed, and the IP address you signed from (this is the evidence trail that the contract is valid)
- Invoices, payment status, and subscription history
- Notes we take during the working relationship (calls, meetings, decisions)
When you pay us
Payments are processed by Stripe. Stripe collects your card details directly — we never see or store the card number, CVC, or expiry date. We only receive the last 4 digits, the card brand, and the payment result. See Stripe's privacy policy.
Automatically (from your browser)
- Strictly necessary cookies — a small session token used to keep you signed in to the admin panel (never set for public visitors).
- Server logs — Vercel automatically records requests (URL, timestamp, response code, IP address) for up to 30 days. This is used for debugging and abuse prevention.
We do notcurrently run Google Analytics, Meta Pixel, or any third-party advertising / tracking cookies. If we ever add analytics we'll update this page and ask for your consent first via the cookie banner.
3. Why we use it, and our lawful basis
Under UK GDPR (Article 6) we must have a lawful basis for every use of your personal data. Here's ours:
| What we do | Why | Lawful basis |
|---|---|---|
| Store your audit-form submission and contact you about it | To arrange and deliver your Leak Audit | Consent (Article 6(1)(a)) — you tick the box when you submit |
| Send you the audit report and follow-up quote | Because you asked for it | Consent, or steps taken at your request prior to entering a contract (Article 6(1)(b)) |
| Deliver services once you're a customer | To do the work you've paid us for | Contract performance (Article 6(1)(b)) |
| Send invoices, take payment, keep tax records | Legal obligation (HMRC, Companies Act) | Legal obligation (Article 6(1)(c)) |
| Store signed contracts with IP / timestamp evidence | To prove the contract is valid if ever disputed | Contract performance and legitimate interest (Article 6(1)(f)) |
| Rate-limit form submissions using your IP address | Stop spam and abuse of the audit form | Legitimate interest (Article 6(1)(f)) |
| Send occasional marketing emails to existing customers about similar services | Follow-up on services you already use | Legitimate interest — PECR Regulation 22 "soft opt-in". You can opt out any time. |
| Send marketing emails to non-customers (prospects) | Only where you've specifically ticked to opt in | Consent (Article 6(1)(a), PECR Regulation 22) |
4. Who we share it with
We use a small number of trusted processors to run the business. Each one is bound by a data processing agreement and only uses your data on our instructions.
| Processor | What they do | Where the data lives |
|---|---|---|
| Supabase | Hosts our database (leads, customers, contracts, notes) | London, UK (EU/UK data residency) |
| Resend | Sends transactional email (audit confirmations, invoices) | EU/US (email routing) |
| Stripe Payments UK Ltd | Card processing and subscription billing | UK/EU/US |
| Vercel | Hosts the website and admin panel | EU (deployment region) with US company controls |
| Cloudflare | DNS and DDoS protection | Global edge network |
A full, current list of sub-processors is available on request from hello@leak-studio.com.
We do not sell your data. We do not share it with advertisers or data brokers.
We may disclose data if legally required (court order, HMRC, ICO request, or to protect our legal rights).
5. International transfers
Most of your data stays in the UK/EU. Where a processor is US-based (Stripe, Resend, Vercel, Cloudflare) transfers are protected under one of the safeguards permitted by UK GDPR — usually the UK International Data Transfer Agreement (IDTA) or the UK Addendum to the EU Standard Contractual Clauses. You can request copies from hello@leak-studio.com.
6. How long we keep it
| What | How long | Why |
|---|---|---|
| Audit-form submissions that never become a customer | 18 months from submission | Long enough to reconnect; short enough to respect the ask |
| Customer records + notes + activity log | 6 years after the last transaction | Limitation Act 1980 — contract disputes |
| Signed contracts | 7 years after end of contract | Contract evidence and audit |
| Invoices and payment records | 7 years | HMRC tax record retention |
| Consent records (audit form ticks) | Duration of the consent + 12 months | ICO accountability |
| Server access logs | Up to 30 days | Debugging and abuse prevention |
7. Your rights
Under UK GDPR you have the right to:
- Access — ask for a copy of the personal data we hold about you (Article 15).
- Rectification— ask us to correct anything that's wrong (Article 16).
- Erasure — ask us to delete data where we no longer need it, or where you withdraw consent (Article 17).
- Restriction — ask us to stop using data while a concern is investigated (Article 18).
- Portability — ask for your data in a machine-readable format so you can move it elsewhere (Article 20).
- Object — object to any use we base on legitimate interest, including marketing (Article 21).
- Withdraw consent — at any time, without affecting anything we did before withdrawal (Article 7(3)).
To exercise any of these, use our data request form or email hello@leak-studio.com. We'll respond within one calendar month (extendable by up to two more months for complex requests, per Article 12(3)).
We may need to verify your identity before releasing data — usually a reply from the email address we already hold for you is enough.
8. Security
We use industry-standard technical and organisational measures to protect your data:
- Encryption in transit (TLS 1.2+) and at rest
- Row-level security on the database — default deny, with access only via authenticated admin sessions or server-side service roles
- Two-factor authentication on all admin accounts
- Onboarding and contract-signing tokens stored as SHA-256 hashes, never in plaintext, and single-use with expiry
- Rate limiting and honeypots on public forms
- Payment card data handled entirely by Stripe (PCI-DSS Level 1) — never touches our servers
9. Data breach
If a breach affects your personal data and is likely to result in risk to your rights, we will notify you without undue delay and inform the Information Commissioner's Office within 72 hours (UK GDPR Articles 33-34). Our full breach response procedure is documented internally.
10. Automated decision-making
We do notmake automated decisions with legal or similarly significant effects about you (UK GDPR Article 22). The Leak Calculator produces an estimate for your benefit — it's not a binding decision.
11. Children
Our services are for businesses. We do not knowingly collect data from anyone under 18. If you believe a child has submitted personal data, email us and we'll delete it.
12. Complaints
If you think we've mishandled your data, please tell us first at hello@leak-studio.com — most things we can fix quickly.
You also have the right to complain to the Information Commissioner's Office:
- Website: ico.org.uk/make-a-complaint
- Phone: 0303 123 1113
- Post: Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF
13. Changes to this policy
We'll update this page whenever our practices change. The "last updated" date at the top always reflects the most recent change. For material changes affecting existing customers we'll email you.
Related: Cookie Policy · Terms of Service · Data request form