Legal

Privacy Policy.

Last updated [DATE] · Version 1.0

This policy explains what personal and business data MarginLabs collects, why we collect it, how we keep it safe, and the rights you have over it. We ask for unusually sensitive information — bank statements, financial accounts — so we hold ourselves to a high standard in how we handle it.

⚠ Template — review before publishing
This is a structured template. Replace every [BRACKETED] field with your real details and have a UK-qualified solicitor review it — particularly the regulated-activity (FCA credit broking) wording — before you rely on it with a real client.
Contents
  1. Who we are
  2. What we collect
  3. Why we collect it & our lawful basis
  4. Who we share it with (sub-processors)
  5. Which law applies (IE · UK · US)
  6. Where it's stored & how it's secured
  7. How long we keep it
  8. Your rights
  9. Cookies
  10. Changes & contact

1 · Who we are

MarginLabs (“we”, “us”, “our”) is an Ireland-based commercial advisory and credit-broking practice serving eCommerce and retail businesses in Ireland, the United Kingdom and the United States. For the purposes of data protection law, we are the data controller of the information described in this policy. As we are established in Ireland, our lead supervisory authority is the Irish Data Protection Commission (DPC).

Legal entity[REGISTERED COMPANY NAME LTD]
Company no.[COMPANIES HOUSE NUMBER]
Registered address[REGISTERED ADDRESS]
Lead authorityIrish Data Protection Commission — dataprotection.ie
Contactprivacy@getmarginlabs.com

2 · What we collect

Depending on how far you progress with us, we may collect:

Information you give us directly

Information we gather to prepare your Read

Information collected automatically

3 · Why we collect it & our lawful basis

PurposeData usedLawful basis (GDPR)
Prepare your funding-readiness “Read” and advise youFinancial, commerce & public-record dataPerformance of a contract / steps prior to a contract
Introduce you to lenders & credit products (broking)Financial & identity data you authorise us to shareConsent & performance of a contract
Operate sign-in & secure the serviceEmail, session tokens, logsLegitimate interests (security)
Comply with legal & regulatory dutiesAs requiredLegal obligation

Where we rely on consent (for example, to share your file with a specific lender), you can withdraw it at any time — see Your rights.

4 · Who we share it with (sub-processors)

We do not sell your data. We share it only with the service providers that help us run MarginLabs, and only as far as needed. Each is bound by a data-processing agreement.

ProviderWhat they doWhere
SupabaseDatabase, encrypted file storage & authenticationEU (Ireland) region
VercelWebsite & application hostingGlobal CDN
ResendSends sign-in & notification emailsEU region
[AI PROVIDER, if used for analysis]Assists with preparing your Read[REGION]
Lenders & finance providersOnly those you explicitly authorise, to assess you for fundingUK / as applicable
On lenders
We never send your file to a lender without your specific say-so. When you ask us to go to market, we tell you exactly who we're approaching.

5 · Which law applies (Ireland · UK · USA)

We serve customers in three regions and apply the protections of each:

Wherever you are, we extend GDPR-level protection as our single standard rather than applying a weaker one by region.

6 · Where it's stored & how it's secured

7 · How long we keep it

DataRetention
Financial documents of a client we work withDuration of engagement + [e.g. 6 years] for legal/tax records, then deleted
Documents of a prospect who does not proceedDeleted within [e.g. 90 days] of last contact, or sooner on request
Account & contact dataUntil you ask us to delete it, subject to legal duties

8 · Your rights

Under the GDPR (and equivalent UK and US-state laws) you have the right to: access your data; correct it; delete it; restrict or object to processing; data portability; and to withdraw consent. You also have the right to complain to your data protection regulator — the Irish Data Protection Commission (dataprotection.ie), the UK ICO (ico.org.uk), or your relevant US state authority.

The easiest way to exercise any of these is our Data Rights page, or email privacy@getmarginlabs.com. We respond within one month, as the law requires.

9 · Cookies

We keep cookies to a minimum. We use only what's needed to keep you securely signed in and to operate the service — we do not use advertising or third-party tracking cookies. [Confirm with your solicitor whether a cookie banner is required for your final setup.]

10 · Changes & contact

We may update this policy as our service evolves. The “last updated” date at the top always reflects the current version, and we'll notify you of material changes.

Data protection contact
Controller[REGISTERED COMPANY NAME LTD]
Post[REGISTERED ADDRESS]
ComplaintsIrish DPC (dataprotection.ie) · UK ICO (ico.org.uk) · relevant US state authority