Legal

Privacy policy

How WeBrandLab collects, uses and protects personal data, and the rights you have under the GDPR and UK GDPR.


Last updated: 21 September 2026

01Who we are

WeBrandLab (“WeBrandLab”, “we”, “us”), operator of webrandlab.com, is the data controller for personal data described here. Full registered entity details are available on request at admin@webrandlab.com.

For any privacy question, request or complaint, write to admin@webrandlab.com. We answer within 30 days.

02What we collect

  • Contact data you send us: name, email, company, website, phone or WhatsApp number, and anything you type into a form, a booking or an email.
  • Booking data: the date, time and answers you give when you book a strategy session through Calendly.
  • Usage data: pages viewed, scroll depth, clicks, approximate location by country, browser, operating system and device type — collected only after you accept analytics cookies.
  • Referral data: the campaign, source and medium tags in the link you arrived through.
  • Technical data: IP address and request logs held by our hosting provider for security and abuse prevention.

We do not collect special category data, and we do not ask for payment card details on this website.

03Why we use it, and on what legal basis

PurposeLegal basis
Replying to your enquiry and running a strategy sessionSteps taken at your request before entering a contract (Art. 6(1)(b))
Delivering a downloadable resource you asked forConsent (Art. 6(1)(a)) and your request (Art. 6(1)(b))
Sending occasional marketing emails to people who asked for themConsent (Art. 6(1)(a)) — withdraw any time via the unsubscribe link
Measuring how the site is used so we can improve itConsent (Art. 6(1)(a)) via the cookie banner
Keeping the site secure and preventing abuseLegitimate interests (Art. 6(1)(f))
Keeping records of contracts and invoicesLegal obligation (Art. 6(1)(c))

04Who we share it with

We never sell personal data. We use a small set of processors, each bound by a data processing agreement:

  • Calendly — scheduling of strategy sessions (United States; EU Standard Contractual Clauses).
  • Supabase — database and storage for form submissions, hosted on our behalf inside our backend.
  • Lovable / Cloudflare — website hosting and content delivery, including security logs.
  • Microsoft Clarity — product analytics and session insights, loaded only with your consent (United States; EU Standard Contractual Clauses).
  • Google Fonts — serves the typefaces used on this site; your browser requests them directly from Google.
  • Our email provider — to receive and answer your messages.

We may also disclose data where the law requires it, or to establish or defend legal claims.

05International transfers

Some of our processors are based outside the EEA, mainly in the United States. Those transfers rely on the European Commission's Standard Contractual Clauses, or on an adequacy decision where one applies. You can request a copy of the safeguards in place.

06How long we keep it

  • Enquiries and booking records: up to 24 months after our last contact, unless a contract is signed.
  • Client contract and billing records: as long as tax and accounting law requires, normally 7 years.
  • Marketing consent records: until you withdraw consent, plus proof of that withdrawal.
  • Analytics data: retained by Microsoft Clarity for up to 13 months.
  • Security and server logs: up to 12 months.

07Your rights

Under the GDPR and UK GDPR you can ask us to:

  • give you a copy of the personal data we hold about you;
  • correct anything that is wrong or incomplete;
  • delete your data where we no longer need it;
  • restrict or object to how we use it, including direct marketing;
  • receive your data in a portable, machine-readable format;
  • withdraw a consent you gave, without affecting what happened before.

Write to admin@webrandlab.com and we will respond within one month. If you are not satisfied, you can complain to your national data protection authority — in Ukraine, the Ukrainian Parliament Commissioner for Human Rights; in the EU, the supervisory authority of the country you live in.

08Security

The site runs over HTTPS. Access to form submissions is restricted by row-level security rules and limited to the people who need it. We review access regularly and keep our dependencies patched.

09Children

This site is aimed at business owners and marketers. We do not knowingly collect data from anyone under 16. If you believe a child sent us data, write to us and we will delete it.

10Changes

We update this policy when our tools or processing change. The date at the top always reflects the current version.