Legal

Privacy Policy

Effective 1 February 2026

This Privacy Policy explains how HypeLab Marketing, a sole trader business operated by Rutvi Ahir and based in London, United Kingdom, collects, uses, and protects personal data obtained through the website hypelabmarketing.co.uk. It applies to all visitors and users of this website and is drafted in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

1. Data Controller

The data controller responsible for your personal data is Rutvi Ahir, trading as HypeLab Marketing, based in London, United Kingdom. For any questions about this policy or your personal data, you can contact the data controller at hello@hypelabmarketing.co.uk.

2. What Data We Collect

When you submit the contact form on our website, we collect the following personal data: your name, email address, phone number, company name, the service you have selected from our list, and any optional message you choose to include. We do not collect any personal data automatically, and we do not gather data from any source other than the information you voluntarily provide through the contact form.

3. How We Use Your Data and Our Legal Basis

We use the data you submit to respond to your enquiry, to provide you with information about the services you have expressed interest in, and to manage any resulting business relationship. Our legal basis for processing your name, email, phone number, company, and selected service is legitimate interest under Article 6(1)(f) of the UK GDPR, as processing is necessary for us to respond to and manage genuine business enquiries. Where you provide an optional message, the legal basis for processing this additional information is your consent, given by the voluntary act of submitting the form. You may withdraw consent at any time by contacting us at hello@hypelabmarketing.co.uk, though this will not affect the lawfulness of any processing carried out before withdrawal.

4. How We Store and Share Your Data

Your contact form submissions are stored in a private MongoDB database and are simultaneously forwarded to the business owner via email using Resend.com as an email delivery service. MongoDB, Inc. and Resend, Inc. act as data processors on our behalf and process your data only as necessary to provide their respective hosting and email transmission services. We do not sell, rent, or share your personal data with any other third parties, marketing networks, or advertising platforms.

5. International Transfers

MongoDB, Inc. and Resend, Inc. are US-based companies, and your personal data may therefore be transferred to and processed in the United States. These transfers are safeguarded by standard contractual clauses approved for use under UK data protection law, as incorporated into each provider's data processing agreements. We have taken reasonable steps to ensure that these processors maintain appropriate security measures in line with UK GDPR requirements.

6. Data Retention

We retain the personal data collected through the contact form for a maximum of 24 months from the date of submission, unless a client relationship is established, in which case data is retained for the duration of that relationship and for up to 24 months after it ends. After the applicable retention period, your data is permanently deleted from our database and email records. You may request earlier deletion at any time by contacting us.

7. Your Rights

Under UK GDPR, you have the right to request access to your personal data, to request rectification of inaccurate data, to request erasure of your data, to request restriction of processing, to data portability, and to object to processing based on legitimate interest. To exercise any of these rights, please email hello@hypelabmarketing.co.uk with the subject line "Data Request" and we will respond within one calendar month. If you are not satisfied with how we handle your data, you have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk or by calling 0303 123 1113.

8. Cookies

This website does not use tracking cookies, analytics cookies, or any third-party advertising cookies. We may use strictly functional cookies that are essential for the website to operate correctly, such as session management. These functional cookies do not collect personal data and do not require your consent under UK cookie regulations.

9. Security

We take appropriate technical and organisational measures to protect your personal data against unauthorised access, loss, alteration, or destruction. Our database is private and access-restricted, and data transmitted via the contact form is sent over encrypted connections. While no method of electronic storage or transmission is completely secure, we review our security practices periodically to ensure they remain appropriate to the nature and volume of data we process.

10. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices or in applicable law. Any changes will be posted on this page with an updated effective date. We encourage you to review this policy periodically.