Privacy policy
This policy explains what personal data Universal Vision Limited collects, why, on what legal basis, how long it is kept, who else sees it and what you can require us to do about it. It is written to meet the UK GDPR and the Data Protection Act 2018, and Regulation (EU) 2016/679 where it applies to visitors and clients in the European Union.
1. Who is responsible
The controller is Universal Vision Limited, company number 16657194, registered office 71–75 Shelton Street, Covent Garden, London WC2H 9JQ, United Kingdom. Data protection matters are handled directly by the director, Edgars Smaukstelis. Contact: info@universalvisionlabs.com or +44 7361 584215.
We are not required to appoint a Data Protection Officer: we are a small organisation, our core activity is not large-scale monitoring, and we do not process special category data on a large scale.
2. What we collect, why, and for how long
| Category | Purpose | Legal basis | Retention |
|---|---|---|---|
| Name, email address, telephone number and the content of your message, submitted through the contact form or sent to us directly | To answer your enquiry and, where it leads to work, to prepare a proposal | Art. 6(1)(b) steps prior to entering a contract; otherwise Art. 6(1)(f) our legitimate interest in responding to enquiries | 24 months from our last contact, then deleted |
| Billing name, billing address, email address, order contents, order number | To perform the contract and to issue and keep invoices | Art. 6(1)(b) performance of a contract; Art. 6(1)(c) legal obligation to retain accounting records | 7 years from the end of the financial year, as required for company records |
| Payment method type, transaction reference, outcome, and the last four digits of the card | To confirm payment, reconcile accounts, process refunds and investigate disputes | Art. 6(1)(b) and Art. 6(1)(c) | 7 years |
| The express request to begin work immediately, and the acknowledgement of the effect on the right to withdraw, recorded at checkout with a timestamp | To evidence that the request was made, as consumer law requires | Art. 6(1)(c) legal obligation | 7 years |
| The brief you complete, and credentials or access you grant to advertising, analytics or website accounts | To perform the service you bought | Art. 6(1)(b) performance of a contract | Access revoked on delivery; briefs kept for 24 months so that follow-up work has context |
| Server and security logs: IP address, user agent, pages requested, timestamps | To keep the site available, detect abuse and investigate incidents | Art. 6(1)(f) our legitimate interest in the security of the service | 12 months |
| Analytics and advertising measurement data set through cookies or similar technologies | To understand how the site is used and whether advertising works | Art. 6(1)(a) your consent, given through the cookie banner | As stated in the cookie policy; withdrawn at any time |
We do not collect special category data, and we ask you not to send it. If it reaches us unsolicited within a brief or a message, we delete it.
3. Where the data comes from
Almost all of it comes from you directly. Server logs are generated automatically when you visit. Where a service requires it, we read data from platforms you have given us access to, such as an advertising account or an analytics property; that data remains yours and section 7 explains our role in relation to it.
4. Providing your data is not compulsory
You are not obliged to give us any personal data. Without billing details and an email address, however, we cannot conclude a contract, issue an invoice or deliver a service; and without account access we cannot perform work that depends on it.
5. Who we share it with
We do not sell personal data, we do not share it for anyone else’s marketing, and we do not disclose it except as set out here. We use a small number of processors, each engaged under a written contract that limits them to our instructions and imposes confidentiality and security obligations:
- our website hosting provider, which stores the site and its database;
- our payment provider, which processes payments on its own hosted pages — we never receive or store your full card number;
- our email and file-sharing providers, through which deliverables and correspondence pass;
- our accountant, for statutory bookkeeping and tax filings.
We also disclose data where we are legally obliged to, to establish or defend legal claims, or with your explicit instruction. Ask us and we will tell you which provider handles a given category of data.
6. Transfers outside the UK and the EEA
Where a provider processes data outside the UK or the European Economic Area, that transfer is made either under an adequacy decision or under the UK International Data Transfer Addendum or the European Commission’s standard contractual clauses, with a transfer risk assessment and supplementary technical measures where appropriate. A copy of the relevant safeguard is available on request from info@universalvisionlabs.com.
7. When we act as your processor
Delivering a service sometimes means handling personal data that belongs to your business — audience lists, CRM exports, form submissions, analytics records. For that data you are the controller and we are the processor, and the following terms apply, forming a data processing agreement between us under Article 28:
- Subject matter and duration: the service you purchased, for its duration.
- Nature and purpose: analysis, configuration, measurement and creative production as described on the service page.
- Instructions: we process only on your documented instructions, including as to international transfers, unless required otherwise by law, in which case we tell you first unless the law forbids it.
- Confidentiality: everyone with access is bound by a duty of confidence.
- Security: access is granted at the lowest useful level, held in a password manager with multi-factor authentication, encrypted in transit, and revoked on delivery.
- Sub-processors: the providers in section 5 only. We give you notice before adding another that would touch your data, and you may object.
- Assistance: we help you respond to data subject requests and, so far as our processing makes it necessary, with impact assessments and prior consultation.
- Breach: we notify you without undue delay and in any event within 48 hours of becoming aware, with the information we hold and the steps taken.
- Deletion or return: on completion or on request we delete or return the data and confirm in writing, retaining only what the law requires and only for that purpose.
- Audit: we make available the information needed to demonstrate compliance and submit to audits on reasonable notice.
8. Your rights
You have the right to be informed, which this policy addresses, and in addition the right to:
- Access — obtain confirmation of whether we process your data and a copy of it;
- Rectification — have inaccurate data corrected and incomplete data completed;
- Erasure — have data deleted where there is no overriding basis to keep it;
- Restriction — have processing paused while a dispute about accuracy or basis is resolved;
- Portability — receive data you gave us, in a structured, machine-readable format, or have it sent to another controller;
- Object — object to processing based on legitimate interest, including any direct marketing, which we then stop;
- Withdraw consent — at any time, without affecting the lawfulness of what was done before.
Email info@universalvisionlabs.com or call +44 7361 584215. We respond within one month and may extend by two further months for complex requests, telling you why within the first month. There is no fee unless a request is manifestly unfounded or excessive. We may ask for proof of identity where we cannot otherwise be sure who is asking.
9. Complaints to a regulator
Tell us first — most issues are quicker to fix directly. You also have the right to complain to a supervisory authority. In the United Kingdom that is the Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF, ico.org.uk. In the European Union it is the authority in the country where you live, work, or where the alleged infringement occurred.
10. Automated decision-making
We do not make decisions producing legal or similarly significant effects about you by automated means, and we do not profile you.
11. Children
Our services are sold to businesses and to adults. We do not knowingly collect data from children, and this site is not directed at them.
12. Security
We apply measures appropriate to the risk: encryption in transit, multi-factor authentication on every account that holds client data, access limited to those who need it, managed devices, and prompt patching. No transmission over the internet is completely secure, and we cannot guarantee absolute security.
13. Changes to this policy
We may update this policy as our processing changes. Where a change materially affects you we will tell you by email before it takes effect. The version published here is always the one that applies.
Company and contact details
These details apply to everything on this page. They are also the details you should use for any formal notice.
| Legal name | Universal Vision Limited |
|---|---|
| Trading name | Universal Vision Labs |
| Company number | 16657194 |
| Place of registration | England and Wales |
| Date of incorporation | 18 August 2025 |
| Registered office | 71–75 Shelton Street, Covent Garden, London WC2H 9JQ, United Kingdom |
| Director | Edgars Smaukstelis |
| info@universalvisionlabs.com | |
| Telephone | +44 7361 584215 |
| VAT number | Not currently VAT registered |
| Response time | Within one working day, Monday to Friday |
| Working language | English |
| Website | universalvisionlabs.com |
The registered office is a correspondence address. All services are performed and delivered remotely; there is no walk-in office and no facility for visitors.