Skip to content

Legal

Privacy policy

Last updated October 5, 2026 · Impact Lab LLC

Draft, pending legal review. This document is a working draft and may change. Highlighted items are still being confirmed. Questions? Email hello@impactlabgroup.com.

This privacy policy explains how Impact Lab LLC (“Impact Lab”, “we” or “us”) collects, uses, shares and protects personal data when you visit impactlabgroup.com (the “site”), contact us, request a free audit or book a consultation, and the rights you have.

It does not cover personal data we handle for clients inside their own ad accounts, analytics tools or customer systems. That work is covered by the client agreement and our data processing agreement.

1. Who we are

Impact Lab LLC is a single-member limited liability company organized in the Commonwealth of Kentucky, USA (Kentucky Secretary of State filing number 1638631.06).

For the personal data described here, Impact Lab LLC is the “controller” under the EU and UK General Data Protection Regulation (GDPR and UK GDPR), and the “business” under US state privacy laws where they apply. Our contact details are in section 12.

[To confirm: whether Impact Lab must appoint a representative in the EU and/or UK under Article 27 of the GDPR and UK GDPR, and if so, their name and contact details]

2. Personal data we collect

Information you give us

  • Contact form: your name, email address, company, website, the topic of your enquiry and your message.
  • Free audit form: your name, email address, company, website, approximate monthly ad budget range, areas of interest and your message.
  • Consultation booking: calls are booked through a Calendly widget embedded on our booking page. The details you enter there, such as your name, email address and chosen time, are collected by Calendly and shared with us so we can hold the call. Calendly’s own privacy notice applies to what you enter in the widget.
  • Emails: your email address, your name if you include it, and anything you write or attach.

Form submissions reach us by email through an email delivery provider. Please do not send us sensitive information, such as health details or ID numbers. If you become a client, your client agreement covers the personal data needed to run the engagement.

Information collected automatically

  • Server logs: like most websites, the site’s hosting provider may record technical information when you visit, such as your IP address, browser and device type, the pages you request and when. This is used to deliver the site and keep it secure. [To confirm: hosting provider and what it logs]
  • Theme preference: if you switch between light and dark mode, your choice is saved in your browser’s local storage. It stays on your device and is not sent to us.
  • Analytics and advertising tools, if enabled: tools such as Google Analytics or the Meta Pixel may use cookies or similar technologies to collect your IP address, device and browser details, the pages you view, how you arrived and what you do on the site. [To confirm: whether any analytics tools or advertising pixels are used on the site, and which ones]

3. How we use personal data and our legal bases

We use personal data only for the purposes below. If you are in the European Economic Area (EEA) or the UK, we must have a legal basis for each use, which we list alongside it.

  • Responding to enquiries and emails. Our legitimate interest in answering people who contact us, or steps you ask us to take before entering into a contract.
  • Preparing your free audit and holding consultations. Steps you ask us to take before entering into a contract.
  • Preparing proposals, providing our services and managing the client relationship. Performance of a contract, or our legitimate interest in working with the business you represent.
  • Running, securing and improving the site, including preventing spam and abuse. Our legitimate interest in a working, safe site.
  • Measuring site use and advertising, if enabled. Your consent, where the law requires it. You can withdraw it at any time.
  • Following up about our services. If we send marketing emails, we will do so only where the law allows, for example with your consent where required, and every email will let you unsubscribe. [To confirm: whether marketing or follow-up emails will be sent]
  • Meeting legal obligations and protecting our rights. Compliance with the law, and our legitimate interest in establishing, exercising or defending legal claims.

Where we rely on legitimate interests, we have weighed them against your rights, and you can object at any time (see section 8).

4. How we share personal data

We do not sell personal data. We share it only with:

  • Service providers that process it on our behalf under contract:
    • website hosting [To confirm: hosting provider, e.g. Vercel]
    • email delivery for form submissions, and our business inbox [To confirm: email delivery provider, e.g. Resend, and the provider hosting the hello@impactlabgroup.com inbox]
    • scheduling: Calendly, for consultation bookings
    • analytics, if enabled [To confirm: analytics provider, if any]
  • Advertising platforms, if pixels are enabled. Platforms such as Meta would receive information about your visit and may use it for their own purposes under their own policies. Under some US state laws this counts as “sharing” for cross-context behavioral advertising, which you can opt out of (see section 8). [To confirm: whether advertising pixels will be used]
  • Professional advisers, such as lawyers and accountants, under a duty of confidentiality.
  • Authorities and others, when the law requires it or to protect our rights, your safety or the safety of others.
  • A buyer or successor, if Impact Lab is involved in a merger, sale or similar transaction.

5. International transfers

Impact Lab is based in the United States, and our service providers may process data in the US or other countries. If you are in the EEA, the UK or Switzerland, your data will be transferred outside your country. Where required, we rely on safeguards such as the European Commission’s Standard Contractual Clauses (with the UK addendum where relevant), or a provider’s certification under the EU–U.S. Data Privacy Framework and its UK and Swiss extensions. Contact us for more information. [To confirm: the transfer safeguard relied on for each service provider]

6. How long we keep personal data

We keep personal data only as long as we need it for the purposes above or as the law requires, then delete or anonymize it.

  • Enquiries, audits and bookings that do not lead to work: [To confirm: retention period, e.g. 24 months after our last contact]
  • Client records: [To confirm: retention period, e.g. the engagement plus the period required for tax and legal purposes]
  • Server logs, analytics data and Calendly bookings: [To confirm: retention period for each, e.g. 14 months for analytics]
  • Theme preference: until you clear your browser’s site data.

7. How we protect personal data

We use reasonable technical and organizational measures, such as encrypted (HTTPS) connections to the site, limiting access to the accounts that hold personal data, and strong passwords with two-factor authentication on those accounts. [To confirm: the security measures actually in place] No method of sending or storing data is completely secure. If a breach affects your personal data, we will notify you and the authorities where the law requires it.

8. Your rights

Depending on where you live, you may have some or all of these rights.

If you are in the EEA or the UK

  • Access: get a copy of the data we hold about you.
  • Correction: fix inaccurate or incomplete data.
  • Deletion: have your data deleted.
  • Restriction: limit how we use your data.
  • Objection: object to uses based on legitimate interests, and to direct marketing at any time.
  • Portability: receive the data you gave us in a machine-readable format, or have it sent to another organization.
  • Withdrawing consent: at any time, without affecting what we did before.
  • Complaints: to your local data protection authority (in the UK, the Information Commissioner’s Office).

If you are in the United States

Residents of California (under the CCPA, as amended by the CPRA) and other states with consumer privacy laws may have the right to know what personal data we collect and get a copy, to correct or delete it, to opt out of its sale, its “sharing” for cross-context behavioral advertising and targeted advertising, to appeal our decision on a request where state law provides it, and not to be treated differently for using these rights.

We do not sell personal data, and we do not ask for sensitive personal information through the site. If advertising pixels are enabled, you can opt out of sharing by emailing us. [To confirm: opt-out method, e.g. a “Do not sell or share my personal information” link, and whether Global Privacy Control signals are honored]

Some of these laws apply only to businesses above certain thresholds, such as annual revenue or the number of people whose data they process. [To confirm: which US state privacy laws apply to Impact Lab, and whether these rights will be offered to all visitors regardless]

How to make a request

Email hello@impactlabgroup.com with “Privacy request” in the subject line. We may need to verify your identity first. Where the law allows, you can use an authorized agent, and we may ask for proof of their authority. We will respond within the time the applicable law requires, for example one month under the GDPR or 45 days under the CCPA, and will tell you if we need to extend it.

9. Cookies, third-party sites and embeds

The site stores your theme preference in your browser’s local storage. Analytics tools, advertising pixels and the Calendly booking embed may also use cookies, as explained in our cookie policy. Third-party websites we link to, and embedded tools like Calendly, handle data under their own policies, and we are not responsible for their practices.

10. Children

The site and our services are not directed to children under 16, and we do not knowingly collect their personal data. If you believe a child under 16 has sent us personal data, contact us and we will delete it.

11. Changes to this policy

We may update this policy from time to time. The date at the top of this page shows when it last changed. We will highlight significant changes on the site.

12. Contact us

For questions or requests about this policy or your personal data: