Privacy Policy
Last updated: 17 July 2026
This Privacy Policy sets out how AUDELAB LTD processes personal data in connection with audelab.team and our digital publishing, EdTech, and software solutions for media platforms, in accordance with UK GDPR and the Data Protection Act 2018.
1. Introduction and Scope
This Privacy Policy explains how AUDELAB LTD ("AUDELAB", "we", "us", or "our") collects, uses, stores, shares, and otherwise processes personal data when you visit https://audelab.team, communicate with us, or use our digital publishing, EdTech, and software solutions for media platforms. We are committed to protecting personal data in accordance with the United Kingdom General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, the Privacy and Electronic Communications Regulations 2003 (PECR) as amended, and other applicable United Kingdom data protection laws.
AUDELAB LTD operates from 11 Wyke Square, Weymouth, DT4 9XP United Kingdom. You may contact our information technology and privacy coordination team by telephone on +44 161 496 0871 or by email at it.team@audelab.team. Please note that email addresses are provided in this Policy as plain text only.
This Policy applies to personal data processed in connection with our website, client onboarding, service delivery for content management systems, e-book and digital publishing platforms, cloud hosting arrangements, analytics relating to service performance, support communications, and related business activities. It does not apply to third-party websites or services that we do not control, even if those services are linked from our materials.
By using our website or engaging our services, you acknowledge that you have read this Privacy Policy. Where we rely on consent as a lawful basis, we will seek that consent in a clear and specific manner. Where you act on behalf of an organisation, you confirm that you are authorised to provide information relating to that organisation and its personnel as reasonably required for the engagement.
2. Data Controller and Contact Details
For the purposes of UK data protection law, AUDELAB LTD is the data controller in respect of personal data that we determine the purposes and means of processing, including website enquiry data, marketing preference data (where applicable), and business contact data used for our own commercial administration.
Where we process personal data solely on documented instructions from a client in the course of providing software, publishing, hosting, or related platform services, we may act as a data processor. In those circumstances, the relevant client remains the controller, and our processing will be governed by the applicable services agreement and data processing terms.
If you have questions about this Policy, wish to exercise your rights, or need to report a personal data concern, please contact AUDELAB LTD at 11 Wyke Square, Weymouth, DT4 9XP United Kingdom, telephone +44 161 496 0871, or email it.team@audelab.team. We aim to acknowledge genuine privacy enquiries promptly and to respond within the statutory timescales.
3. Categories of Personal Data We Process
3.1 Identity and contact data
We may process your name, job title, organisation name, postal address, telephone number, and email address when you contact us, request information, negotiate or enter into a contract, or receive service communications. Business contact details may include departmental identifiers and preferred communication channels.
3.2 Account and authentication data
If you are provided with access to a client portal, content management environment, publishing dashboard, or support system administered by us, we may process usernames, authentication credentials in hashed or otherwise secured form, role assignments, access logs, multi-factor authentication status, and security challenge responses. We do not store passwords in recoverable plaintext.
3.3 Technical and usage data
When you visit audelab.team or interact with our hosted platforms, we may automatically collect Internet Protocol addresses, browser type and version, device type, operating system, referring URLs, pages viewed, timestamps, approximate location derived from IP address at a coarse level, and diagnostic logs necessary for security and performance. Cookie and similar technology details are described further in our Cookie Policy.
3.4 Transaction and billing data
For contracted services we may process purchase order references, invoice details, payment status, bank or payment method identifiers to the extent necessary for administration, VAT information, and records of commercial correspondence. Payment card data, if processed at all, is handled through regulated payment providers and is not stored on our public website systems.
3.5 Content and publishing-related data
In delivering digital publishing and media platform services, we may process metadata associated with editorial workflows, contributor identifiers supplied by the client, content classification tags, distribution schedules, and usage analytics that the client elects to enable. The substantive editorial content itself is typically controlled by the client; where such content contains personal data, the client remains responsible for ensuring a lawful basis and appropriate notices.
3.6 Support and correspondence data
We retain records of support tickets, chat or email threads, call notes, escalation histories, and related attachments that you or your organisation provide. These records help us resolve incidents, improve service quality, and demonstrate contractual performance.
3.7 Special category and criminal offence data
We do not seek to collect special category personal data or criminal offence data through our website. Please do not submit such information unless we have expressly requested it for a lawful and documented purpose and identified an Article 9 UK GDPR condition. If you inadvertently submit such data, we will take reasonable steps to delete or restrict it unless retention is required by law.
4. Sources of Personal Data
We obtain personal data directly from you when you complete forms, send emails, speak with our team, create or use accounts, or otherwise interact with our services. We may also receive personal data from your employer or contracting organisation where you are nominated as a contact, project stakeholder, or authorised user.
Technical data may be generated automatically by our systems, security tools, and analytics configurations. We may receive limited business contact information from professional referrals, public business directories, or event organisers where such collection is lawful and proportionate.
If you provide personal data relating to another individual, you must ensure that you have a lawful basis to do so and that the individual has been provided with information equivalent to this Policy where required.
5. Purposes and Lawful Bases for Processing
We process personal data only where a lawful basis under Article 6 UK GDPR applies. Depending on the context, we rely on one or more of the following bases.
5.1 Performance of a contract
We process identity, contact, account, billing, and service delivery data where necessary to enter into or perform a contract with you or your organisation, including provisioning platform access, delivering publishing and software services, providing support, and managing invoices and renewals.
5.2 Legitimate interests
We process certain data where necessary for our legitimate interests, provided those interests are not overridden by your interests or fundamental rights and freedoms. Such interests include securing our systems, preventing fraud and misuse, improving website and service performance, maintaining business records, responding to general enquiries, managing supplier relationships, and asserting or defending legal claims. We conduct balancing assessments where appropriate.
5.3 Legal obligation
We process and retain data where necessary to comply with legal obligations applicable in the United Kingdom, including tax, accounting, company, regulatory, and law enforcement disclosure requirements.
5.4 Consent
Where required by PECR or otherwise, we obtain consent for non-essential cookies, certain electronic marketing, or optional processing activities. You may withdraw consent at any time without affecting the lawfulness of processing based on consent before withdrawal.
5.5 Specific purpose mapping
- Website operation and security: technical logs, IP addresses, and security events under legitimate interests and, where applicable, legal obligation.
- Responding to enquiries and proposals: contact and correspondence data under legitimate interests or steps prior to entering a contract.
- Client onboarding and service delivery: identity, account, and project data under contract and legitimate interests.
- Hosting, CMS, and publishing platforms: operational and user account data under contract; client-instructed processing under processor arrangements.
- Billing and finance: transaction data under contract and legal obligation.
- Service improvement and quality assurance: aggregated or pseudonymised usage insights under legitimate interests.
- Marketing communications where permitted: contact data under consent or soft opt-in rules under PECR, as applicable.
- Dispute management and compliance: relevant records under legitimate interests and legal obligation.
6. Cookies and Similar Technologies
Our website and certain platform interfaces use cookies and similar technologies. Essential cookies are necessary for core functionality and security. Analytics and preference cookies, where used, are described in our Cookie Policy at cookie-policy.html. You can manage non-essential cookies through our cookie controls and your browser settings. For further detail on categories, retention of cookie identifiers, and third-party tools, please review the Cookie Policy, which forms part of our transparency framework alongside this Privacy Policy.
7. How We Share Personal Data
We do not sell personal data. We share personal data only where necessary for the purposes described in this Policy and subject to appropriate safeguards.
7.1 Service providers and processors
We engage carefully selected service providers to support hosting, infrastructure, email delivery, customer relationship management, security monitoring, analytics (where enabled), professional advisory services, and payment administration. These providers process personal data on our instructions or under appropriate contractual terms and are required to implement suitable technical and organisational measures.
7.2 Clients and authorised users
Where you interact with a platform operated for a client, certain account and activity information may be visible to that client's administrators in accordance with the client's configuration and policies.
7.3 Professional advisers and corporate transactions
We may share data with legal, accounting, insurance, and other professional advisers where necessary. In the event of a merger, acquisition, restructuring, or sale of assets, personal data may be transferred to relevant parties under appropriate confidentiality and data protection arrangements.
7.4 Legal and regulatory disclosures
We may disclose personal data where required by law, court order, regulatory request, or to protect the rights, property, or safety of AUDELAB LTD, our clients, users, or the public. We will challenge overly broad requests where we consider it lawful and appropriate to do so.
8. International Transfers
AUDELAB LTD is established in the United Kingdom. Personal data is primarily processed within the United Kingdom and, where applicable, the European Economic Area. If we transfer personal data to a third country, we will ensure that an appropriate transfer mechanism is in place, such as an adequacy regulation recognised under UK law, the UK International Data Transfer Agreement, the UK Addendum to the EU Standard Contractual Clauses, or another lawful mechanism permitted by UK GDPR Chapter V.
Where clients instruct us to host or process data in specific regions, we will follow those documented instructions to the extent technically and contractually feasible. You may request further information about transfer safeguards by contacting it.team@audelab.team.
9. Retention of Personal Data
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, including satisfying legal, accounting, or reporting requirements, and resolving disputes. Retention periods vary by category.
- Website enquiry records: typically retained for up to twenty-four months after the last meaningful contact unless a longer period is needed for ongoing discussions or legal claims.
- Contract and billing records: retained for the duration of the commercial relationship and thereafter for periods required by UK tax and company law, commonly up to six years or longer where necessary.
- Account and access logs: retained for security and audit purposes for periods aligned to operational risk, often between ninety days and twenty-four months depending on system type.
- Support tickets: retained for the service term and a reasonable period thereafter to evidence performance and assist future support.
- Cookie identifiers: retained in accordance with the periods stated in the Cookie Policy.
- Marketing preference records: retained while consent or soft opt-in remains valid and for a short period afterwards to demonstrate compliance.
Where data is no longer required, we will delete it or irreversibly anonymise it. Backup systems may retain residual copies for a limited period until overwritten in accordance with our backup rotation schedules. Legal holds may suspend ordinary deletion where necessary.
10. Security Measures
We implement technical and organisational measures designed to protect personal data against unauthorised access, alteration, disclosure, or destruction. Measures may include access controls based on least privilege, encryption in transit using modern TLS configurations, encryption at rest where appropriate for hosted environments, secure development practices, vulnerability management, logging and monitoring, staff awareness, and contractual security obligations for processors.
No method of transmission or storage is completely secure. Absolute security cannot be guaranteed. You are responsible for maintaining the confidentiality of credentials issued to you and for using strong, unique passwords and multi-factor authentication where available. Please notify us promptly at it.team@audelab.team if you suspect unauthorised access to your account or to systems we administer for you.
11. Your Rights Under UK GDPR
Subject to conditions and exemptions in the Data Protection Act 2018 and UK GDPR, you have the following rights in relation to personal data we hold about you as controller.
11.1 Right of access
You may request confirmation of whether we process your personal data and, where we do, access to that data together with certain information about the processing.
11.2 Right to rectification
You may request correction of inaccurate personal data and completion of incomplete personal data.
11.3 Right to erasure
You may request deletion of personal data in specific circumstances, including where the data is no longer necessary, consent is withdrawn and no other lawful basis applies, or the processing is unlawful. This right is not absolute.
11.4 Right to restriction
You may request that we restrict processing in certain cases, such as while we verify accuracy or assess an objection.
11.5 Right to data portability
Where processing is based on consent or contract and carried out by automated means, you may request to receive personal data you provided to us in a structured, commonly used, and machine-readable format, and to transmit that data to another controller where technically feasible.
11.6 Right to object
You may object to processing based on legitimate interests, including profiling based on those interests. You also have an absolute right to object to direct marketing at any time.
11.7 Rights related to automated decision-making
We do not make solely automated decisions producing legal or similarly significant effects about individuals visiting our website. If this changes, we will provide meaningful information about the logic involved and your related rights.
11.8 Right to withdraw consent
Where we rely on consent, you may withdraw it at any time by contacting us or using available unsubscribe or cookie preference tools.
11.9 How to exercise your rights
To exercise any right, contact AUDELAB LTD at 11 Wyke Square, Weymouth, DT4 9XP United Kingdom, telephone +44 161 496 0871, or email it.team@audelab.team. We may need to verify your identity before fulfilling a request. We will respond without undue delay and in any event within one month, extendable by a further two months for complex or numerous requests where permitted by law. We will inform you of any extension and the reasons for it.
If we act only as a processor for a client, we may need to redirect your request to the relevant controller or assist that controller in accordance with our contract.
12. Children's Privacy
Our website and business services are directed to organisations and professionals. We do not knowingly collect personal data from children under sixteen through audelab.team. If you believe a child has provided personal data to us, please contact it.team@audelab.team so that we can take appropriate steps to delete the information.
13. Marketing Communications
We may send service-related messages that are necessary for the performance of a contract or requested information. Separately, we may send commercial communications about our digital publishing, EdTech, and software solutions where permitted by PECR and UK GDPR. Where consent is required, we will obtain it. Where the soft opt-in applies to existing customers in relation to similar products or services, we will provide a clear opportunity to refuse or opt out at the time of collection and in each subsequent message.
You can opt out of marketing emails at any time by using the unsubscribe mechanism or by contacting it.team@audelab.team. Opting out of marketing does not affect transactional or service communications.
14. Personal Data Breaches
We maintain procedures to detect, investigate, and respond to personal data breaches. Where we are the controller and a breach is likely to result in a risk to individuals' rights and freedoms, we will notify the Information Commissioner's Office without undue delay and, where feasible, not later than seventy-two hours after becoming aware of it, unless an exemption applies. Where the risk is high, we will also communicate to affected individuals without undue delay in accordance with Articles 33 and 34 UK GDPR.
Where we act as a processor, we will notify the relevant controller without undue delay after becoming aware of a personal data breach affecting data processed on that controller's behalf, providing information reasonably available to us to assist the controller with its own assessment and notification obligations.
15. Third-Party Links and Embedded Content
Our website may contain links to third-party websites, repositories, documentation portals, or social platforms. Those third parties operate their own privacy practices, which we do not control. We encourage you to review their policies before providing personal data. Embedded media or scripts, if used, may allow third parties to collect technical data about your interaction subject to your cookie preferences and browser settings.
16. Data Protection Impact Assessments and Records
Where required by Article 35 UK GDPR, we conduct data protection impact assessments for processing that is likely to result in a high risk to individuals. We maintain records of processing activities proportionate to our size and processing context, including purposes, categories of data subjects and personal data, recipients, retention, and security measures. Clients who engage us as a processor should maintain their own records and provide us with processing instructions that are lawful and documented.
17. Processor Obligations When Acting for Clients
When AUDELAB LTD processes personal data as a processor, we will process only on documented instructions from the controller unless required to do otherwise by United Kingdom law. We will ensure that persons authorised to process personal data are subject to confidentiality obligations, implement appropriate security measures, engage sub-processors only with appropriate authorisation and flow-down terms, assist the controller with data subject rights and security obligations to a reasonable extent, delete or return personal data at the end of the service as instructed subject to legal retention requirements, and make available information necessary to demonstrate compliance, including through audits agreed in the contract.
Clients remain responsible for the lawfulness of their instructions, the accuracy of notices provided to data subjects, and obtaining any consents required for their publishing, educational, or media platform use cases.
18. Roles in Digital Publishing and EdTech Contexts
Digital publishing and EdTech platforms frequently involve layered roles. A publisher client may be the controller of subscriber and contributor data. An educational institution may be the controller of learner records. AUDELAB may provide the software, hosting, and technical operations that enable those controllers to process data. In such cases, responsibility for content moderation policies, age-appropriate design considerations for learning products, parental notices where required, and curriculum data governance rests primarily with the relevant controller.
We design our systems with privacy by design and by default principles in mind, including configurable access roles, audit logging options, and data export tooling where specified in the service description. Specific feature availability depends on the product package and statement of work.
19. Automated Tools, Analytics, and Profiling
We may use analytics to understand aggregate website traffic and improve user experience. Where analytics cookies are non-essential, they will be activated only with consent as described in the Cookie Policy. We do not create marketing profiles that produce legal or similarly significant effects. Platform analytics provided to clients as a service feature are configured under the client's instructions and remain the client's responsibility as controller.
20. Complaints and the Information Commissioner's Office
We hope to resolve privacy concerns directly. Please contact us first at it.team@audelab.team or by post to 11 Wyke Square, Weymouth, DT4 9XP United Kingdom. You also have the right to lodge a complaint with the Information Commissioner's Office (ICO), the UK supervisory authority for data protection. Further information is available from the ICO's public guidance resources. Nothing in this Policy limits your statutory rights.
21. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in law, technology, or our business practices. The "Last updated" date at the top of this page will be revised when changes are published. Material changes will be highlighted on the website or communicated to clients through appropriate channels where required. Continued use of the website after an update constitutes acknowledgement of the revised Policy, except where consent is required for a particular processing activity.
22. Additional Disclosures for Service Environments
22.1 Cloud hosting environments
Personal data processed within cloud hosting environments under our management is protected through network segmentation where appropriate, hardened images, patching regimes, backup policies, and access authentication. Client-specific isolation depends on the architecture selected in the statement of work, which may include shared multi-tenant components with logical separation or dedicated resources.
22.2 Content management systems
CMS environments may store editorial drafts, user comments if enabled, media assets, and workflow history. Administrators should apply least-privilege roles and remove access promptly when staff change. We can assist with configuration guidance but the client's administrators remain responsible for day-to-day user governance.
22.3 E-book and media distribution platforms
Distribution platforms may process purchaser or subscriber identifiers, device entitlements, reading progress metrics if enabled, and licence tokens. The client determines which metrics are collected and how end-user notices are presented. AUDELAB processes such data as instructed for platform operation and support.
22.4 Support diagnostics
To resolve incidents we may access system logs and, with authorisation, limited production data. Access is logged and limited in time and scope. We ask clients not to share unnecessary special category data in support tickets.
23. Lawful Requests and Transparency Reports
Where we receive a binding legal request for disclosure of personal data, we will validate the request, disclose only what is legally required, and, where permitted, notify the affected client or individual. We do not provide voluntary bulk access to personal data for unrelated commercial purposes.
24. Contact Summary
AUDELAB LTD, 11 Wyke Square, Weymouth, DT4 9XP United Kingdom. Telephone: +44 161 496 0871. Email: it.team@audelab.team. Website: https://audelab.team. For privacy rights, breach notifications to us as processor, or policy questions, please use the contact details above. Related documents include our Cookie Policy, Terms of Service, and Terms and Conditions, available through the legal navigation on this page.
25. Glossary of Key Terms
For ease of reference, the following terms have the meanings commonly attributed under UK data protection law. "Personal data" means any information relating to an identified or identifiable natural person. "Processing" means any operation performed on personal data, whether or not by automated means. "Controller" means the person who determines the purposes and means of processing. "Processor" means the person who processes personal data on behalf of the controller. "UK GDPR" means the United Kingdom General Data Protection Regulation as retained and amended in UK law. "Data Protection Act 2018" means the UK statute that sits alongside UK GDPR. "Data subject" means the identified or identifiable natural person to whom personal data relates.
This glossary is provided for convenience and does not replace the statutory definitions. In the event of conflict, the statutory definitions prevail. If you require clarification of any term used in this Policy, please contact it.team@audelab.team.
26. Detailed Lawful Basis Assessments
For each major processing activity we document the purpose, necessity, and lawful basis. Where legitimate interests are relied upon, we identify the interest, assess whether the processing is necessary to achieve it, and consider the impact on individuals, including expectations arising from the nature of a business-to-business relationship in digital publishing and software services.
In relation to security monitoring, our legitimate interest in protecting systems, clients, and users against unauthorised access, malware, denial-of-service activity, and fraud is compelling. Monitoring is limited to what is proportionate, and retention of security logs is time-bounded. Individuals retain the right to object, subject to compelling legitimate grounds where applicable.
In relation to business development correspondence following an inbound enquiry, we rely on steps prior to entering a contract or legitimate interests in responding professionally. We do not place enquirers on marketing lists without an appropriate PECR basis.
27. Categories of Recipients in Greater Detail
Infrastructure and hosting providers may receive technical identifiers, encrypted content stores, and administrative account data necessary to operate virtual machines, containers, object storage, and network services. Email and ticketing providers may process message content and metadata for communication delivery. Analytics providers, where consented, may receive pseudonymous usage events.
Professional services firms may receive limited personal data when advising on commercial, regulatory, or dispute matters. Insurance providers may receive claim-related information. Regulators and courts may receive data where disclosure is mandated. We evaluate each category of recipient for competence, security posture, and contractual readiness before engagement.
28. Data Minimisation and Accuracy Practices
We design forms and onboarding processes to request only information that is relevant to the stated purpose. Optional fields are marked where practicable. We encourage clients to apply the same principle within platforms we operate for them, including avoiding free-text fields that solicit unnecessary sensitive information.
Accuracy is supported by allowing authorised users to update profile information, by periodic review of dormant accounts, and by correcting data when we become aware of inaccuracies. If you believe data we hold is incorrect, please contact it.team@audelab.team with sufficient detail for us to investigate.
29. Staff Access and Confidentiality
Access to personal data by AUDELAB personnel is granted on a need-to-know basis according to role. Staff and contractors are bound by confidentiality obligations and are expected to complete data protection awareness appropriate to their responsibilities. Privileged access to production environments is logged and reviewed. Misuse of personal data is a disciplinary matter and may also constitute a legal breach.
30. Sub-processors and Change Notices
Where we act as a processor, the services agreement or data processing addendum identifies the approach to sub-processor authorisation, which may be general authorisation with notice or prior specific authorisation. We impose data protection terms on sub-processors that are no less protective than those applying to us in material respects. Clients may object to a new sub-processor within the contractual window where such a right is granted, and we will discuss commercially reasonable alternatives.
31. End-of-Engagement Data Return and Deletion
Upon termination of a processing engagement, and subject to the contract, we will delete or return personal data processed as a processor, except for copies required to be retained under United Kingdom law or copies remaining in immutable backups until rotation completes. Clients should export required content before the end of any wind-down period. Certification of deletion may be provided where expressly agreed.
32. Interaction with Consumer Law and Platform Users
Where our client's end users are consumers in the United Kingdom, the client's consumer-facing terms and privacy notices govern the end-user relationship. AUDELAB's Privacy Policy explains our own processing and does not replace the client's notices. If you are an end user of a client platform and wish to exercise rights, you should ordinarily contact the client as controller. We will assist controllers with rights requests in accordance with our processor obligations.
Nothing in this Policy excludes liability that cannot be excluded under applicable law, including under the Consumer Rights Act 2015 where it applies to a qualifying consumer relationship with AUDELAB LTD directly.
33. Recorded Calls and Meeting Notes
We do not routinely record telephone calls. If a call is to be recorded for training or quality purposes, we will inform participants in advance where required. Video conference meetings may generate transcripts or recordings if a participant enables those features; participants should disable such features if not appropriate. Meeting notes that contain personal data are retained as correspondence records under the retention principles above.
34. Accessibility of Privacy Information
We aim to present privacy information in clear language. If you require this Policy in an alternative accessible format, please contact it.team@audelab.team or telephone +44 161 496 0871 and we will take reasonable steps to assist.
