Privacy policy

This policy explains what personal data Universal Vision Limited collects, why, on what legal basis, how long it is kept, who else sees it and what you can require us to do about it. It is written to meet the UK GDPR and the Data Protection Act 2018, and Regulation (EU) 2016/679 where it applies to visitors and clients in the European Union.

1. Who is responsible

The controller is Universal Vision Limited, company number 16657194, registered office 71–75 Shelton Street, Covent Garden, London WC2H 9JQ, United Kingdom. Data protection matters are handled directly by the director, Edgars Smaukstelis. Contact: info@universalvisionlabs.com or +44 7361 584215.

We are not required to appoint a Data Protection Officer: we are a small organisation, our core activity is not large-scale monitoring, and we do not process special category data on a large scale.

2. What we collect, why, and for how long

Category Purpose Legal basis Retention
Name, email address, telephone number and the content of your message, submitted through the contact form or sent to us directly To answer your enquiry and, where it leads to work, to prepare a proposal Art. 6(1)(b) steps prior to entering a contract; otherwise Art. 6(1)(f) our legitimate interest in responding to enquiries 24 months from our last contact, then deleted
Billing name, billing address, email address, order contents, order number To perform the contract and to issue and keep invoices Art. 6(1)(b) performance of a contract; Art. 6(1)(c) legal obligation to retain accounting records 7 years from the end of the financial year, as required for company records
Payment method type, transaction reference, outcome, and the last four digits of the card To confirm payment, reconcile accounts, process refunds and investigate disputes Art. 6(1)(b) and Art. 6(1)(c) 7 years
The express request to begin work immediately, and the acknowledgement of the effect on the right to withdraw, recorded at checkout with a timestamp To evidence that the request was made, as consumer law requires Art. 6(1)(c) legal obligation 7 years
The brief you complete, and credentials or access you grant to advertising, analytics or website accounts To perform the service you bought Art. 6(1)(b) performance of a contract Access revoked on delivery; briefs kept for 24 months so that follow-up work has context
Server and security logs: IP address, user agent, pages requested, timestamps To keep the site available, detect abuse and investigate incidents Art. 6(1)(f) our legitimate interest in the security of the service 12 months
Analytics and advertising measurement data set through cookies or similar technologies To understand how the site is used and whether advertising works Art. 6(1)(a) your consent, given through the cookie banner As stated in the cookie policy; withdrawn at any time

We do not collect special category data, and we ask you not to send it. If it reaches us unsolicited within a brief or a message, we delete it.

3. Where the data comes from

Almost all of it comes from you directly. Server logs are generated automatically when you visit. Where a service requires it, we read data from platforms you have given us access to, such as an advertising account or an analytics property; that data remains yours and section 7 explains our role in relation to it.

4. Providing your data is not compulsory

You are not obliged to give us any personal data. Without billing details and an email address, however, we cannot conclude a contract, issue an invoice or deliver a service; and without account access we cannot perform work that depends on it.

5. Who we share it with

We do not sell personal data, we do not share it for anyone else’s marketing, and we do not disclose it except as set out here. We use a small number of processors, each engaged under a written contract that limits them to our instructions and imposes confidentiality and security obligations:

  • our website hosting provider, which stores the site and its database;
  • our payment provider, which processes payments on its own hosted pages — we never receive or store your full card number;
  • our email and file-sharing providers, through which deliverables and correspondence pass;
  • our accountant, for statutory bookkeeping and tax filings.

We also disclose data where we are legally obliged to, to establish or defend legal claims, or with your explicit instruction. Ask us and we will tell you which provider handles a given category of data.

6. Transfers outside the UK and the EEA

Where a provider processes data outside the UK or the European Economic Area, that transfer is made either under an adequacy decision or under the UK International Data Transfer Addendum or the European Commission’s standard contractual clauses, with a transfer risk assessment and supplementary technical measures where appropriate. A copy of the relevant safeguard is available on request from info@universalvisionlabs.com.

7. When we act as your processor

Delivering a service sometimes means handling personal data that belongs to your business — audience lists, CRM exports, form submissions, analytics records. For that data you are the controller and we are the processor, and the following terms apply, forming a data processing agreement between us under Article 28:

  • Subject matter and duration: the service you purchased, for its duration.
  • Nature and purpose: analysis, configuration, measurement and creative production as described on the service page.
  • Instructions: we process only on your documented instructions, including as to international transfers, unless required otherwise by law, in which case we tell you first unless the law forbids it.
  • Confidentiality: everyone with access is bound by a duty of confidence.
  • Security: access is granted at the lowest useful level, held in a password manager with multi-factor authentication, encrypted in transit, and revoked on delivery.
  • Sub-processors: the providers in section 5 only. We give you notice before adding another that would touch your data, and you may object.
  • Assistance: we help you respond to data subject requests and, so far as our processing makes it necessary, with impact assessments and prior consultation.
  • Breach: we notify you without undue delay and in any event within 48 hours of becoming aware, with the information we hold and the steps taken.
  • Deletion or return: on completion or on request we delete or return the data and confirm in writing, retaining only what the law requires and only for that purpose.
  • Audit: we make available the information needed to demonstrate compliance and submit to audits on reasonable notice.

8. Your rights

You have the right to be informed, which this policy addresses, and in addition the right to:

  • Access — obtain confirmation of whether we process your data and a copy of it;
  • Rectification — have inaccurate data corrected and incomplete data completed;
  • Erasure — have data deleted where there is no overriding basis to keep it;
  • Restriction — have processing paused while a dispute about accuracy or basis is resolved;
  • Portability — receive data you gave us, in a structured, machine-readable format, or have it sent to another controller;
  • Object — object to processing based on legitimate interest, including any direct marketing, which we then stop;
  • Withdraw consent — at any time, without affecting the lawfulness of what was done before.

Email info@universalvisionlabs.com or call +44 7361 584215. We respond within one month and may extend by two further months for complex requests, telling you why within the first month. There is no fee unless a request is manifestly unfounded or excessive. We may ask for proof of identity where we cannot otherwise be sure who is asking.

9. Complaints to a regulator

Tell us first — most issues are quicker to fix directly. You also have the right to complain to a supervisory authority. In the United Kingdom that is the Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF, ico.org.uk. In the European Union it is the authority in the country where you live, work, or where the alleged infringement occurred.

10. Automated decision-making

We do not make decisions producing legal or similarly significant effects about you by automated means, and we do not profile you.

11. Children

Our services are sold to businesses and to adults. We do not knowingly collect data from children, and this site is not directed at them.

12. Security

We apply measures appropriate to the risk: encryption in transit, multi-factor authentication on every account that holds client data, access limited to those who need it, managed devices, and prompt patching. No transmission over the internet is completely secure, and we cannot guarantee absolute security.

13. Changes to this policy

We may update this policy as our processing changes. Where a change materially affects you we will tell you by email before it takes effect. The version published here is always the one that applies.

Company and contact details

These details apply to everything on this page. They are also the details you should use for any formal notice.

Legal name Universal Vision Limited
Trading name Universal Vision Labs
Company number 16657194
Place of registration England and Wales
Date of incorporation 18 August 2025
Registered office 71–75 Shelton Street, Covent Garden, London WC2H 9JQ, United Kingdom
Director Edgars Smaukstelis
Email info@universalvisionlabs.com
Telephone +44 7361 584215
VAT number Not currently VAT registered
Response time Within one working day, Monday to Friday
Working language English
Website universalvisionlabs.com

The registered office is a correspondence address. All services are performed and delivered remotely; there is no walk-in office and no facility for visitors.