Skip to main content
slab

Privacy notice

How Slab handles your data.

Last updated: 11 May 2026

1. Who we are

Slab Software Ltd ("we", "us", "our") is a company registered in England and Wales, company number 17215158. We trade as "Slab" and operate getslab.uk. Slab Software Ltd is the data controller for the personal data described in this notice.

For privacy enquiries, contact us through the form on the site or email hello@getslab.uk. Our registered office address is on the Companies House public register.

2. What personal data we collect

We collect personal data in two ways:

  • Forms you submit on the site. The contact form and the foundation-client form collect your name, email address, company name, role and any details you choose to share in the message. The foundation-client form additionally collects an optional phone number and the ISO standards your business holds.
  • Aggregated, anonymous site usage data. We use Plausible Analytics to count pageviews, referral sources and device types. Plausible does not use cookies, does not collect IP addresses, and does not track individuals across sites or sessions.

We do not use advertising cookies. We do not track visitors across the web. We do not collect special category data.

3. Why we collect it and our lawful basis

We process your personal data for the following purposes:

  • To respond to your enquiry. When you submit a form, we use the details to reply, set up a call, or send you the information you requested. Lawful basis: legitimate interests (responding to a direct enquiry from you).
  • To improve the site and the product. Aggregated, anonymous analytics help us understand which pages are useful and which are not. Lawful basis: legitimate interests (improving a service we provide).
  • To meet legal obligations. If a regulator or court requires us to retain or produce records, we will. Lawful basis: legal obligation.

4. Who we share it with

We share your personal data only with the third-party providers required to operate the site and respond to your enquiry. Each is a sub-processor under our control:

  • Formspree (US-based) processes form submissions and routes them to our inbox. Cross-border transfer is governed by Standard Contractual Clauses.
  • Plausible Analytics (EU-based) processes anonymous, aggregated site usage data.
  • Netlify (US-based) hosts the website. Server logs are retained for security and reliability purposes only. Cross-border transfer is governed by Standard Contractual Clauses.
  • Mailchimp (US-based) will be used for opt-in email when lead magnets and the newsletter ship. We will update this notice at that point. Cross-border transfer is governed by Standard Contractual Clauses.

We do not sell your personal data. We do not share it with advertising networks. We do not enrich it with data purchased from third parties.

5. International transfers

Some of our sub-processors are based outside the UK and the European Economic Area, including in the United States. Where personal data is transferred outside the UK, we rely on the UK International Data Transfer Addendum to the European Commission's Standard Contractual Clauses, or on the UK extension to the EU-US Data Privacy Framework where applicable.

All customer data within the Slab product itself (the evidence engine accessed at app.slab.uk by paying customers) is hosted in the United Kingdom and does not leave the UK without explicit customer consent. That arrangement is governed by a separate Data Processing Addendum, not this notice.

6. How long we keep it

We hold your personal data only for as long as we have a clear reason to:

  • Form submissions are kept for up to 24 months after our last contact with you, then deleted unless you have become a customer.
  • Customer records are kept for the duration of the contract plus six years (in line with HMRC retention requirements).
  • Aggregated analytics data is retained indefinitely in anonymised form.

You can request earlier deletion at any time. See section 7.

7. Your rights

Under UK GDPR you have the right to:

  • Be informed about how your personal data is used (this notice)
  • Access the personal data we hold about you
  • Request correction of inaccurate data
  • Request erasure of your data ("the right to be forgotten")
  • Restrict or object to processing
  • Receive a portable copy of your data
  • Withdraw consent at any time, where consent is the lawful basis

To exercise any of these rights, contact us through the form on the site or email hello@getslab.uk. We will respond within one month.

8. How we keep your data secure

We use HTTPS across the site, role-based access control on internal systems, and encryption at rest and in transit on all sub-processor platforms. We do not retain your data in spreadsheets, on local laptops, or in any system without access controls.

If a breach occurs that is likely to result in a high risk to your rights and freedoms, we will notify you and the Information Commissioner's Office (ICO) without undue delay.

9. Cookies

getslab.uk does not use cookies for advertising or cross-site tracking. The site uses no cookies at all in its current configuration. Plausible Analytics, our chosen analytics provider, is cookie-free by design.

If we add cookies in the future (for example, to remember a logged-in session inside the product itself), we will update this notice and present a clear consent choice on first use.

10. Complaints

If you believe we have mishandled your personal data, contact us first through the form so we can investigate. If you are not satisfied with our response, you have the right to lodge a complaint with the Information Commissioner's Office:

Information Commissioner's Office
Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
Helpline: 0303 123 1113
ico.org.uk

11. Updates to this notice

We will update this notice when our processing materially changes (for example, when a new sub-processor is added or when the production product launches). Material changes will be flagged at the top of the page, and the "last updated" date will be revised.

Contact us about your data

Use the contact form or email hello@getslab.uk for any privacy enquiry. We will respond within one working day for routine questions and within one month for formal data subject rights requests.