Legal
Privacy Notice
Last updated: 31 August 2026This notice explains how Lokuva Tech Ltd ("we", "us") collects and uses personal data, and what rights you have. It is written to meet the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
1. Who we are
Lokuva Tech Ltd is a private company limited by shares, registered in England and Wales under company number 16839733, with its registered office at 168 Humber Road, Coventry, England, CV3 1BG. We are the data controller for the personal data described in this notice.
For anything relating to data protection, write to support@lokuvatech.org with [ADMIN] in the subject line.
2. What this website collects
This site is a set of static files. It has no contact form, no account system, no analytics, no advertising pixels and no cookies of our own. We do not build a profile of visitors and we cannot identify you from browsing alone.
Two things nonetheless involve a third party:
- Web hosting. Our hosting provider processes standard server request information — IP address, timestamp, requested file, browser user-agent — in order to serve the page and to keep the service secure. This is ordinary technical logging and we do not use it for marketing.
-
Google Fonts. Typefaces are requested from Google's font servers,
which means your IP address is visible to Google when a page loads. If you would
rather avoid that, blocking
fonts.googleapis.comandfonts.gstatic.comleaves the site fully readable in your system fonts.
3. Personal data we hold, and why
- Enquiry correspondence. When you email us we hold your name, email address, and whatever you choose to put in the message. We use it to answer you and to keep a record of the conversation. Lawful basis: legitimate interests — responding to someone who has contacted us — or steps towards a contract at your request.
- Client and supplier records. For an engagement we hold contact details for the people involved, contractual documents, project correspondence, and billing information. Lawful basis: performance of a contract, and legal obligation for accounting records.
- Training attendance. For courses we hold the names of attendees and, where the client asks for it, a record of attendance. Lawful basis: performance of our contract with the client organisation.
- Data we process for clients. While delivering software, migration or campaign work we may access personal data held in a client's systems. In that case the client is the controller and we act as a processor under a written agreement, using the data only on their documented instructions.
4. What we never do
- Sell, rent or trade personal data.
- Add an enquirer to a marketing list without them asking to be on it.
- Use client data to train models or build products.
- Track visitors across other websites.
5. Who we share data with
Only where it is necessary to run the business, and only with processors under contract: our email and file-storage provider, our website host, our accountant, and — where an engagement requires it — the cloud or advertising platform being used, always in accounts belonging to the client. We disclose data to anyone else only where the law requires it.
Where a provider stores data outside the UK, we rely on UK adequacy regulations or on the International Data Transfer Agreement or Addendum, as applicable.
6. How long we keep it
- Enquiries that do not become work: up to 24 months, then deleted.
- Client project records: for the engagement plus 6 years, matching the limitation period for contract claims in England and Wales.
- Accounting records: 6 years from the end of the relevant accounting period, as required by the Companies Act 2006.
- Data processed on a client's behalf: returned or deleted at the end of the engagement, as set out in the agreement with that client.
7. Security
Access to systems is restricted to the directors and any personnel working on the relevant engagement, protected by multi-factor authentication. Credentials are held in a password manager, devices are encrypted, and client production access is granted only where the work requires it and removed when it does not. No system is perfectly secure; if a breach occurs that is likely to result in a risk to your rights, we will notify the Information Commissioner's Office within 72 hours and tell you where the law requires it.
8. Your rights
Under the UK GDPR you may ask us to:
- confirm what personal data we hold about you and give you a copy (access);
- correct anything inaccurate or incomplete (rectification);
- delete data where we no longer have a reason to hold it (erasure);
- restrict how we use it while a concern is investigated;
- provide it in a portable, machine-readable form;
- stop processing carried out on the basis of our legitimate interests (objection).
Write to support@lokuvatech.org. We respond within one calendar month and do not charge a fee. We may ask you to confirm your identity first so that we do not disclose someone's data to the wrong person.
9. Complaints
If you are unhappy with how we have handled your data, please tell us first so we can put it right. You also have the right to complain to the Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF — ico.org.uk.
10. Changes to this notice
If we change how we handle personal data we will update this page and the date at the top. Where a change materially affects an existing client or an ongoing engagement, we will tell them directly rather than relying on this page.
See also our cookie notice and terms of use.