This Privacy Policy explains how RegimeLab ("we", "us", "our") collects, uses, and protects your personal data when you use regimelab.io, my.regimelab.io, our tools, our API, and our emails (the "Service"). We are the data controller for the personal data described here. RegimeLab is based in the United Kingdom, and we handle personal data in line with the UK GDPR and the Data Protection Act 2018.
We do not ask for or store payment card details directly. If and when paid plans begin, payments will be handled by a third-party payment processor, and your card details will be held by that processor, not by us.
We send the weekly read and related updates only to people who asked for them. Every email includes an unsubscribe link, and you can opt out at any time. Unsubscribing stops the marketing emails; we may still send essential Service messages if you have an account (for example, security or billing notices).
We do not sell your personal data. We share it only with service providers who help us run the Service, under appropriate agreements. These may include our email delivery provider, hosting and infrastructure providers, analytics providers, and, in future, a payment processor. We may also disclose data where required by law or to protect our rights, the Service, or users.
Some of our providers may process data outside the UK. Where they do, we take steps to ensure your data receives an appropriate level of protection, for example through approved safeguards such as the UK International Data Transfer Agreement or an adequacy decision.
We keep personal data for as long as needed for the purposes above. If you unsubscribe from the weekly read and have no account, we remove or anonymise your email within a reasonable period, except where we need to keep a record to honour your unsubscribe request. Account data is kept while your account is active and for a reasonable period afterward.
Under UK data protection law you have the right to access your data, to have inaccurate data corrected, to have data erased in certain circumstances, to restrict or object to certain processing, to data portability, and to withdraw consent at any time. To exercise any of these, email hello@regimelab.io. You also have the right to complain to the Information Commissioner's Office (ICO) at ico.org.uk, though we would appreciate the chance to help first.
We use a small number of cookies and similar technologies to run the site, remember preferences, and understand usage. You can control cookies through your browser settings. Where required, we will ask for your consent to non-essential cookies.
We take reasonable technical and organisational measures to protect your data. No method of transmission or storage is completely secure, so we cannot guarantee absolute security, but we work to protect your information and to respond appropriately if something goes wrong.
The Service is not directed at anyone under 18, and we do not knowingly collect data from children.
We may update this policy from time to time. If we make material changes, we will take reasonable steps to let you know. The "last updated" date at the top shows when it last changed.
Questions about your data or this policy: hello@regimelab.io.
Draft note (remove before launch): This is a first draft for review under UK GDPR. Have it checked by a qualified adviser before launch. Confirm the controller's legal name and address, your actual sub-processors (email, hosting, analytics, payments), your cookie set, and your true retention periods, and register with the ICO if required. Fill in the last-updated date.