Privacy Policy

Privacy Policy

Last updated: June 2026

Processing of personal data

This policy (this "Privacy Policy") describes how we at Lusobo process your personal data, including data collected through our website and through the provision of our services, when we act as the controller of that personal data.

We process personal data in accordance with the UK General Data Protection Regulation (the "UK GDPR") and the Data Protection Act 2018, and — to the extent that we process personal data of individuals in the European Economic Area (the "EEA") — in accordance with Regulation (EU) 2016/679 (the "EU GDPR") and applicable national implementing laws. In this Privacy Policy, references to the "GDPR" mean the UK GDPR and/or the EU GDPR, as applicable to the relevant processing. Where there is any conflict, the regime applicable to you on the basis of your location applies.

Lusobo is a trading name of LUSOBO LTD, a company registered in England and Wales with company number 17209602. Our registered office is at 128 City Road, London, EC1V 2NX, United Kingdom.

This Privacy Policy does not apply to the extent that we process your personal data in the role of a processor (within the meaning of Article 28 of the GDPR) when providing our services to businesses, companies and/or other entities who are our customers and who use our platform and services for professional purposes. The terms on which we process personal data on behalf of our customers are set out in the agreements between us and our customers — principally our Terms & Conditions and a separate Data Processing Agreement pursuant to Article 28(3) of the GDPR.

If you have any questions about our processing of your personal data, or you wish to exercise your rights, you are always welcome to contact us by email at privacy@lusobo.com.

Categories of personal data, purpose and lawful basis

In the course of running our business — including in our direct interactions with you, when providing our services, and through our website — we collect and receive personal data in different ways and from different sources. The personal data processed in this connection is set out below. The Article references below apply equally under the UK GDPR and the EU GDPR, which share the same numbering.

Customer management

In order to administer, manage and develop our relationship with our customers, we process personal data about you as a customer or a potential customer. As part of our customer management, the following types of information are processed:

  1. Ordinary personal data. This includes identification and contact information such as names, email addresses and postal addresses of customers, owners of the customer and/or contact persons, as well as representatives of the customer. We also process information about our relationship with the customer, including correspondence, and information about accounts receivable and outstanding amounts. In certain cases we collect credit information about customers.
  2. The lawful basis for the processing is Article 6(1)(b) of the GDPR, under which personal data may be processed where necessary for the performance of a contract (in this case the engagement or the prospective engagement). Personal data may also be processed where necessary for the purposes of our legitimate interests, including establishing and developing a relationship with a customer (Article 6(1)(f) of the GDPR). There may also be situations where we store your personal data even where we do not enter into an agreement.

Marketing

We process personal data in connection with marketing activities, including courses, events and the sending of newsletters. This processing is necessary in order to provide services to interested businesses.

  1. In this context, ordinary personal data is processed, including name, contact information and any interests or topic preferences, as well as language.
  2. The lawful basis for processing personal data in connection with courses, events, newsletters and similar is our legitimate interest in marketing our business (Article 6(1)(f) of the GDPR). Where required by the Privacy and Electronic Communications Regulations 2003 ("PECR") in the UK, or by the ePrivacy Directive 2002/58/EC as implemented in the relevant EEA member state, we rely on your consent for electronic marketing.
  3. We will only send you newsletters or other marketing material where we have an appropriate lawful basis to do so. If you no longer wish to receive such information, you may notify us using the contact details above or use the unsubscribe link in any marketing email, and we will then stop sending you the relevant material.

Business operations

In connection with our internal business operations, we process personal data of owners or employees of our suppliers, customers and business partners.

  1. In this respect, ordinary personal data is processed, including name, place of work and contact information, as well as information about the relationship and correspondence.
  2. The lawful basis is Article 6(1)(b) of the GDPR, under which processing is necessary for the performance of a contract to which the data subject is a party, or where necessary for the purposes of our legitimate interests (Article 6(1)(f)). Where processing is based on our legitimate interest, that interest is communicating with suppliers and partners, which is essential to the operation of our business model.

Our website

When you visit our website and cloud-based software, we collect and process information about you in connection with our use of cookies for functional, statistical and marketing purposes (for example, to optimise our website and target advertising).

You can find an overview of the types of cookies we use, and how to delete them, in our Cookie Policy.

  1. Ordinary personal data is processed in the form of your IP address in connection with our use of cookies. In addition, we process the following information about you: demographic information, interests, geography, and information about your browser, device and service provider.
  2. The lawful basis for non-essential cookies is your consent (Article 6(1)(a) of the GDPR, read together with PECR in the UK and the ePrivacy Directive as implemented in the EEA). For strictly necessary cookies, our lawful basis is our legitimate interest in operating a secure and functional website (Article 6(1)(f) of the GDPR).
  3. When you use the contact form on our website, we collect your name and email address. We also collect your telephone number and company name if you provide them. We process this data so that you can contact us and so that we can handle your request. The lawful basis is usually Article 6(1)(b) of the GDPR, which permits processing for the performance or initiation of a contract. If your request is not aimed at concluding a contract with us, the lawful basis is Article 6(1)(f) of the GDPR; our legitimate interest is in providing a low-threshold contact option.

Social media

We are active on several social media platforms, including LinkedIn and X. When you interact with us on these platforms, you make information available to us and to the platform — for example, when you respond to, comment on or share our posts, or follow us. We process ordinary information about you in the form of, for example, identification information, contact information and your profile photo. In some cases we may also share content (such as a news item) in which your name appears.

  1. The lawful basis for the processing is our legitimate interest in marketing ourselves on social media and in knowledge sharing (Article 6(1)(f) of the GDPR).
  2. Where a social media provider and Lusobo jointly determine the purposes and means of processing in respect of certain insights, we and the provider may be considered joint controllers for that processing.
  3. Information on social media is deleted when we delete a post, or when you delete your comment, share, reaction, "like" or follow.

Disclosure and transfer of personal data

We may share your personal data with the following categories of recipients:

  1. Trusted service providers acting as our data processors who help us operate and support our business. Data processing agreements in accordance with Article 28(3) of the GDPR have been concluded with these processors to ensure the protection of your data. Transfers to these processors take place only in accordance with the agreements concluded. These third parties have limited access to your personal data, may use it only to perform the agreed services, and are prohibited from disclosing or using it for any other purpose.
  2. Regulators, public authorities, courts and law enforcement bodies — including, where applicable, HM Revenue & Customs (HMRC) and other UK or EEA regulators and tax authorities — where we are required or permitted by law to do so.
  3. Professional advisers, insurers and banks.
  4. Third parties to whom we may choose to sell, transfer or merge parts of our business or assets, or with whom we merge. If a change happens to our business, the new owners may use your personal data in the same way as set out in this Privacy Policy.

International transfers

In connection with our IT operations (including hosting, development and support), we may in certain cases transfer personal data to organisations established in a country outside the United Kingdom and/or the EEA. Where we make such a transfer, we ensure that your personal data is adequately protected by relying on one of the following safeguards, as applicable:

  1. an adequacy decision adopted by the European Commission (for transfers subject to the EU GDPR) and/or UK adequacy regulations (for transfers subject to the UK GDPR);
  2. the EU Standard Contractual Clauses (for transfers subject to the EU GDPR), and/or the International Data Transfer Agreement (IDTA) or the UK Addendum to the EU Standard Contractual Clauses (for transfers subject to the UK GDPR); or
  3. the implementation of additional measures where required.

You can obtain further information about our transfer of your personal data to third countries by contacting us.

Data security

We have put in place appropriate technical and organisational security measures to prevent your personal data from being accidentally lost, used or accessed in an unauthorised way, altered or disclosed. We limit access to your personal data to those employees, agents, contractors and other third parties who have a business need to know, and they are subject to strict confidentiality obligations. We have procedures in place to deal with any suspected personal data breach and will notify you and the relevant supervisory authority (the ICO in the UK and/or the competent EEA authority) of a breach where we are legally required to do so.

Retention and erasure

In general, we process your information only for as long as is necessary to fulfil the purpose of the processing. The following retention periods apply:

Customer management

In connection with customer management, we generally store your information for three years from the end of the year in which the matter was closed, unless otherwise required by law or in the case of original documents such as contracts. Personal data processed for accounting and bookkeeping purposes is stored together with the accounting records for the current year plus six years in line with UK requirements (Companies Act 2006 and HMRC requirements); where longer statutory retention periods apply under the national law of an EEA member state in which we operate, we apply the longer period.

Business operations

Information about you as a supplier or business partner is stored for up to three years after the end of the year during which the delivery took place or the cooperation ended. Personal data processed for accounting and bookkeeping purposes is stored for the current year plus six years (or any longer period required by applicable national law).

Marketing and website

We store your information for up to six months after you have participated in an event or unsubscribed from our newsletter. For the deletion of cookies, see our Cookie Policy.

Your rights

As a data subject, you have certain rights under the GDPR when your personal data is processed. These are set out below. If you wish to exercise one or more of your rights, please contact us in writing at the email address above, stating your full name and email address. You may be asked to provide further identification. You can generally exercise your rights at any time; however, exercising your rights must not adversely affect the rights and freedoms of others, and in such cases we may refuse to comply with your request in whole or in part to the extent permitted by the GDPR and other applicable law.

Right of access

You have the right to obtain access to your personal data being processed by us. On request, we can provide information about the categories of personal data we process about you, the purposes of the processing, the recipients to whom the data has been disclosed, and so on. We will provide a copy of your personal data undergoing processing. If you request further copies, we may charge a reasonable fee based on administrative costs. If a request is manifestly unfounded or excessive, we may charge a reasonable fee or refuse to act on the request.

Right to rectification

You have the right to have inaccurate or misleading personal data corrected. Where we do not agree that the data is inaccurate, we are not obliged to correct it but will record that you do not consider the data to be correct.

Right to erasure

In certain cases, you have the right to have your personal data erased — for example, where we no longer have a purpose for processing it, or where you object to processing for direct marketing or under Article 6(1)(f) of the GDPR. Where we can demonstrate overriding legitimate grounds, or where processing is necessary for the establishment, exercise or defence of legal claims, we are not obliged to erase your data.

Right to restriction of processing

In certain cases you have the right to obtain a restriction of processing — for example, where you contest the accuracy of the personal data, or where you have objected to processing based on legitimate interests under Article 6(1)(f). In such cases we will only store your data until your objection has been considered. If we lift a restriction, you will be notified in advance.

Right to object

On grounds relating to your particular situation, you have the right to object to our processing of your personal data where it is based on legitimate interests (Article 6(1)(f) of the GDPR). If you object, we will no longer process your personal data unless we can demonstrate overriding legitimate grounds, or the processing is necessary for the establishment, exercise or defence of legal claims. You always have the right to object to processing for direct-marketing purposes.

Right to data portability

In certain cases you have the right to receive your personal data in a structured, commonly used and machine-readable format and to have that data transmitted to another controller. This right applies only where processing is based on a contract (Article 6(1)(b)) or your consent (Article 6(1)(a)) and is carried out by automated means.

Automated decision-making

Your personal data is not subject to decisions based solely on automated processing, including profiling, that produce legal effects concerning you or similarly significantly affect you.

Right to withdraw consent

Where we process your personal data on the basis of your consent, you can withdraw that consent at any time in respect of any future processing, by emailing us at privacy@lusobo.com.

Complaints

If you are not satisfied with the way we process your personal data, you can complain to us using the contact details above. You also have the right to lodge a complaint with a supervisory authority:

  1. In the United Kingdom: the Information Commissioner's Office (ICO) — ico.org.uk · helpline 0303 123 1113 · Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF.
  2. In the EEA: the data protection authority of the member state of your habitual residence, place of work or place of the alleged infringement. For example, the Hellenic Data Protection Authority (HDPA, dpa.gr) in Greece, or the Office of the Commissioner for Personal Data Protection (dataprotection.gov.cy) in Cyprus.

Changes to this Privacy Policy

We update this Privacy Policy on an ongoing basis so that it is always current. The date of the most recent version is shown at the top of this page.

LUSOBO LTD · Company number 17209602 · 128 City Road, London, EC1V 2NX, United Kingdom