Privacy Policy

Last updated: 9 August 2026

This Privacy Policy describes how KeslerLab Ltd (“KeslerLab”, “we”, “us”) handles personal data in connection with the website at keslerlab.co. We are a small, independent product studio registered in England & Wales, with our registered office in Mildenhall, Suffolk, and we act as the data controller for the personal data described below. We aim to collect as little personal data as possible, and to be clear about what we do with it. If anything on this page is unclear, write to us at info@keslerlab.com.

1. Who we are

Data controller
KeslerLab Ltd
Company number
16804759, registered in England & Wales
Incorporated
23 October 2025
Registered office
82a James Carter Road, Mildenhall, Suffolk, IP28 7DE, United Kingdom
Data protection contact
info@keslerlab.com

We are not required to appoint a Data Protection Officer. Privacy matters are handled directly by the company's officers, who can be reached at the email address above.

2. What we collect

Information you send us. There is no contact form on this site, and the site itself does not gather any information you type. If you choose to write to us by email, we receive your email address, whatever name you sign with, and the contents of your message — along with anything you attach. We only use it to answer you.

Technical information. Our hosting provider records standard server access logs, including IP address, user agent, referrer, and the URL requested. These are used to operate the site, diagnose errors, and protect against abuse. We do not use them to build a profile of you.

Language preference. The site is published in English and Turkish. When you pick a language, that choice is stored in a single functional cookie so the site opens in the same language next time. See section 3.

What we do not collect:

  • Third-party analytics or audience measurement
  • Advertising trackers, retargeting pixels, or social media pixels
  • Behavioural profiling or automated decision-making
  • Special category data (health, biometrics, political or religious views, and similar)
  • Payment or card details — the site takes no payments

We do not sell personal data, and we do not share it with advertisers or data brokers.

3. Cookies

keslerlab.co sets one cookie, and it exists solely to remember which language you chose. It is a functional (strictly necessary) cookie: without it, the site cannot honour your language choice on the next visit.

Name
nf_lang
Purpose
Remembers your language preference (English or Turkish) so the site loads in that language
Type
Functional / strictly necessary — not used for tracking
Lifetime
1 year from the moment you select a language
Set by
keslerlab.co (first party)
Read by
Our hosting provider's language redirect, so you land on the right version of the page
Shared with third parties
No

We set no tracking, advertising, or analytics cookies of any kind. Strictly necessary cookies may additionally be set by our hosting provider for security purposes; these are not used to identify you across sites.

You can delete or block cookies through your browser settings at any time. If you remove nf_lang, nothing breaks — the site simply falls back to the language your browser advertises, and asks again the next time you choose.

4. Lawful basis for processing

We rely on the following lawful bases under the UK GDPR:

  • Legitimate interests — operating and securing the website, keeping server logs, and replying to enquiries you initiate. Our interest is running a functioning, non-abusive website, balanced against the very limited data involved.
  • Consent — where you voluntarily send us information by email, and where you actively choose a language, which is what causes the nf_lang cookie to be written.
  • Legal obligation — where we must retain records, for example basic accounting and tax records.
  • Performance of a contract — where correspondence turns into an engagement and processing your details is necessary to deliver the work.

5. How long we keep it

Email correspondence
Up to 24 months, unless a working relationship begins — in which case for the duration of the engagement plus any statutory retention period
Server access logs
Up to 30 days
Language cookie (nf_lang)
1 year, or until you delete it
Accounting records
As required by UK law, typically six years from the end of the relevant financial year

When a retention period ends, data is deleted or anonymised. We do not keep personal data “just in case”.

6. Who we share it with

We use a small number of trusted service providers to run the site and our email — principally web hosting and content delivery, and email infrastructure. These providers process data on our behalf, under contract, only on our instructions, and only for the purpose of providing their service to us.

We may also disclose personal data where we are legally required to do so, or where it is necessary to establish, exercise, or defend legal claims. Beyond that, we do not sell personal data and we do not transfer it to third parties for their own marketing purposes.

7. International transfers

Some of our service providers operate outside the United Kingdom, which means personal data may be processed in other countries. Where that happens, we rely on an approved transfer mechanism — a UK adequacy decision where one exists, or the UK International Data Transfer Agreement (or the UK Addendum to the EU Standard Contractual Clauses) together with a transfer risk assessment where it does not.

8. Your rights

Under the UK GDPR you have the right to:

  • Access the personal data we hold about you, and receive a copy of it
  • Have inaccurate data corrected without undue delay
  • Have your data erased, where there is no overriding reason for us to keep it
  • Restrict processing, or object to processing carried out on the basis of legitimate interests
  • Receive your data in a portable, machine-readable format where processing is based on consent or contract
  • Withdraw consent at any time, without affecting anything we did lawfully before you withdrew it

To exercise any of these rights, email info@keslerlab.com. We will respond within one month. There is no charge, unless a request is manifestly unfounded or excessive.

You also have the right to complain to the UK Information Commissioner's Office (ICO) at ico.org.uk. We would appreciate the chance to address your concern first, but that is entirely your choice.

9. Security

We apply reasonable technical and organisational measures to protect personal data, including encryption in transit (HTTPS across the whole site), access controls with multi-factor authentication on our systems, and the principle of least privilege. Only the people who need access to correspondence have it.

No transmission over the internet is ever completely secure. If a personal data breach occurs that is likely to risk your rights and freedoms, we will notify the ICO within 72 hours and inform affected individuals where the law requires it.

10. Children

This site is aimed at businesses and professional audiences. It is not directed at children, and we do not knowingly collect personal data from anyone under 13. If you believe a child has sent us personal data, write to info@keslerlab.com and we will delete it.

11. Changes to this policy

We may update this policy as the site or our practices change. The current version always lives at this address, and the revision date shown at the top of the page tells you when it last changed materially. Where a change significantly affects how we use your personal data, we will make that clear rather than relying on the date alone.

12. Contact

Questions about this policy, or about the personal data we hold, can be sent to:

KeslerLab Ltd
Registered in England & Wales, Company No. 16804759
Address
82a James Carter Road, Mildenhall, Suffolk, IP28 7DE, United Kingdom
Email
info@keslerlab.com
Back to home