Legal
Privacy & Cookie Policy
1. Who we are
Aldemis Foundry is a service provided by Aldemis: Aldemis Partners Ltd registration number 17130393, registered address 86-90 Paul Street, London, EC2A 4NE, United Kingdom ("Aldemis", "we", "us"). Aldemis is the controller of the personal data described in this policy.
You can contact us about anything in this policy at contact@aldemis.com.
This policy explains how we handle personal data in connection with this website and with enquiries about the Aldemis Foundry service. It is written to comply with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018, as amended by the Data (Use and Access) Act 2025 ("DUAA"), and with the Privacy and Electronic Communications Regulations 2003 ("PECR") as amended by the DUAA with effect from 5 February 2026.
2. The personal data we collect
This website is deliberately light on data collection. We collect personal data in the following situations:
- When you book a call. Booking links on this site take you to our scheduling provider, OneCal, where you provide your name, email address and chosen appointment time, and optionally any notes you add.
- When you email us. We receive your email address, name and the contents of your message.
- When you become a client. We collect business contact details, information about your company and product, and the information needed to deliver the service and administer billing. Client engagements are governed by our engagement terms in addition to this policy.
- Technical data. Our hosting provider records standard server logs (such as IP address, browser type and pages requested) for security and service operation. We do not use this information to identify individuals.
We do not knowingly collect data from anyone under 18, and this website is not directed at children.
3. How and why we use your data
| Purpose | Data used | Lawful basis |
|---|---|---|
| Responding to enquiries and holding intro calls | Contact details, booking information, correspondence | Legitimate interests (responding to people who contact us), or steps taken at your request prior to entering a contract |
| Delivering the Foundry service to clients | Contact details, company and product information, account and billing data | Performance of a contract; legal obligation (accounting and tax records) |
| Keeping the website and our systems secure | Technical and server log data | Legitimate interests (network and information security) |
| Occasional relevant follow-up after an enquiry | Contact details | Legitimate interests (business-to-business communication). You can opt out at any time and every message includes a way to do so |
We do not sell personal data, and we do not use personal data for automated decision-making that produces legal or similarly significant effects about you.
4. Cookies and similar technologies
This website does not set cookies. No analytics, advertising or tracking cookies are placed by us, and no consent banner is required because there is nothing to consent to.
Two third-party points you should be aware of:
- Fonts. The site loads typefaces from Google Fonts. Your browser requests the font files from Google's servers, which involves Google receiving your IP address. Google states it does not use these requests to set cookies or build profiles.
- Booking. When you follow a booking link you leave this site and use OneCal, which operates under its own privacy and cookie policies.
If we introduce analytics in future. Under PECR as amended by the DUAA (in force 5 February 2026), certain low-risk cookies — including those used solely for statistical purposes to improve the service, and those customising appearance or functionality — no longer require consent, provided we give you clear and comprehensive information about them and a free and simple way to opt out. If we ever introduce such cookies, we will update this policy to describe them and provide that opt-out before they are used. Any cookies falling outside the statutory exemptions (for example, advertising cookies) would only ever be set with your prior consent.
5. Who we share data with
We share personal data only with service providers who help us operate, under contracts that restrict how they may use it:
- Our website hosting provider (server operation and security)
- OneCal (call scheduling)
- Google (font delivery, as described above)
- Our email, document and business software providers
- Professional advisers (accountants, lawyers, insurers) where necessary
We may also disclose personal data where required by law, or as part of a business reorganisation or transfer, in which case this policy would continue to apply to it.
6. International transfers
Some of our service providers process data outside the UK, including in the United States. Where they do, we rely on safeguards recognised under UK law: the UK's adequacy regulations (including the UK–US Data Bridge for certified US organisations), or the ICO's International Data Transfer Agreement or Addendum, as applicable.
7. How long we keep data
- Enquiries that don't proceed: up to 12 months from our last contact, then deleted.
- Client records: for the duration of the engagement and up to 6 years afterwards, in line with limitation periods and accounting requirements.
- Server logs: retained by our hosting provider for short rolling periods for security purposes.
8. Your rights
Under UK data protection law you have the right to:
- Access the personal data we hold about you
- Have inaccurate data corrected and, in certain circumstances, have data erased
- Restrict or object to our processing, including objecting at any time to direct marketing
- Receive data you provided to us in a portable format, where processing is based on contract or consent
- Withdraw consent at any time, where we rely on consent
To exercise any of these rights, email contact@aldemis.com. We will respond within one month, as the law requires, and we will never charge you for a reasonable request.
9. Complaints
If you are unhappy with how we have handled your personal data, you have a statutory right (under section 164A of the Data Protection Act 2018, introduced by the DUAA and in force from 19 June 2026) to complain to us directly. We maintain an internal complaints procedure: we will acknowledge your complaint within 30 days of receiving it, look into it properly, and tell you the outcome without undue delay. Complaints can be made by email to contact@aldemis.com with the subject line "Data protection complaint".
You also have the right to complain to the Information Commissioner's Office (ICO) at any time: ico.org.uk, or by phone on 0303 123 1113. We would, however, welcome the chance to address your concerns first.
10. Security
We apply technical and organisational measures appropriate to the risk, including encrypted connections (HTTPS), access controls on our systems, and careful selection of service providers. No internet service can be guaranteed absolutely secure, but we take the protection of your data seriously and review our measures regularly.
11. Changes to this policy
We will update this policy when our practices or the law change, and the effective date above will always reflect the current version. Material changes affecting existing clients will be notified directly.