01The short version
We do not run analytics, advertising or tracking cookies on this website. We do not sell or share personal data for marketing. Most of the personal data we hold sits inside the software we publish, and belongs to the people who use it — that is covered by section 3 and, in full, by each product's own privacy notice. Beyond that we hold enquiries people send us and the records of the clients we work with.
The rest of this page sets out the detail required by the UK GDPR and the Data Protection Act 2018. If you only care about one thing, Your rights is the section you want.
02Who we are
AntCodeLabs Limited (“AntCodeLabs”, “we”, “us”) is a private limited company registered in England and Wales under company number 17411249. We trade as AntCodeLabs and operate this site at antcodelabs.ai. For the personal data described in this policy, AntCodeLabs Limited is the data controller.
You can contact us about anything in this policy at hello ( at ) antcodelabs.ai — please put “Privacy” in the subject line so it reaches the right person quickly.
When we handle personal data on behalf of a client during an engagement, we act as a processor rather than a controller, and that client's own privacy notice applies. Our GDPR and Data Protection Statement covers that role.
We are also the controller for the personal data in our own apps — see section 3.
03Our apps
We also build and run our own products. Right now that means Partyyy, the Party Operating System, at partyyy.party — a platform for organising parties, invitations, guests and everything around them.
For Partyyy, AntCodeLabs Limited is the data controller. It has its own privacy notice, and that notice — not this page — is the one that governs it. What follows is a summary so you know what sort of processing sits behind the product:
- Hosts hold accounts: name, email, account details, billing records and login activity.
- Guests are invited by a host, and what is held about them is what the party needs — name, contact details, whether they are coming, and any preferences the host asked for.
- Dietary requirements and allergies are health data, which the UK GDPR treats as a special category. They are held only where someone chooses to give them, used only to cater, and can be left blank.
- Photographs uploaded by hosts and guests, and images generated by the product's AI features.
- Engagement records, including whether an invitation email was opened — invitations carry a tracking image so a host can tell.
Hosts and guests are in different positions: a host decides who to invite and what to ask them, while we provide the platform that makes it possible. Partyyy's own GDPR statement works through that split properly.
Nothing in Partyyy is used for advertising, and nothing is sold. The full detail is in Partyyy's privacy policy, terms and AI policy.
04What we collect
When you email us. Your name, email address, and whatever you choose to put in the message and any attachments. There is no contact form on this site — the contact link opens your own email client — so we only ever receive what you send.
When we work together. Business contact details for the people involved in an engagement, correspondence, contractual and project records, and invoicing details.
When you visit this site. Our web server keeps standard technical logs: IP address, date and time, the page requested, HTTP status, and the browser's user-agent string. These exist to keep the service running and secure, not to build a profile of you.
What we do not collect. No analytics or measurement scripts. No advertising or social media pixels. No tracking or consent cookies — which is why you are not being asked to dismiss a cookie banner. No profiling and no automated decision-making that produces legal or similarly significant effects.
Your theme preference
If you use the light/dark switch, your choice is saved in your browser's localStorage
under the key theme. It stays on your device, is never transmitted to us, and clearing your
browsing data removes it. It is a preference you asked for, not a tracker.
05Fonts loaded from Google
This site loads its typefaces from Google Fonts (fonts.googleapis.com and
fonts.gstatic.com). That means your browser makes a request to Google when you load a page,
and Google receives your IP address and user-agent as part of it. We do not receive that data, and no
cookie is set by the font request.
We are naming it because it is the only third party this site talks to, and because self-hosting the fonts would remove it. If you would rather avoid the request entirely, a content blocker or a privacy-focused browser will stop it.
06Why we have it, and our lawful basis
- Replying to enquiries
- Legitimate interests — we cannot answer a question without reading it and writing back.
- Delivering an engagement
- Performance of a contract with you, or legitimate interests where our contract is with your employer.
- Invoicing, accounts and tax
- Legal obligation, and our legitimate interest in running the business properly.
- Server logs, security, abuse prevention
- Legitimate interests — keeping the site available and protecting it from attack.
- Establishing or defending legal claims
- Legitimate interests, and legal obligation where a claim requires it.
Where we rely on legitimate interests, we have considered whether our interest is overridden by your rights and freedoms, and concluded it is not — the processing is limited, expected, and does not involve profiling or disclosure for marketing. You can object at any time (see Your rights), and we will stop unless we have compelling grounds to continue.
We do not send marketing emails to people who have not asked for them. If we ever do, it will be on the basis of consent or the soft opt-in under PECR, and every message will carry a working unsubscribe link.
07How long we keep it
- Enquiries that go nowhere
- Up to 24 months from the last contact, then deleted.
- Client and engagement records
- Six years after the engagement ends — the limitation period for contract claims, and the period HMRC expects records to be kept.
- Invoices and accounting records
- Six years from the end of the relevant accounting period, as required by law.
- Web server logs
- A short rolling window — normally no more than 30 days — unless a log is retained for a specific security investigation.
- Client personal data we process
- For as long as the client instructs, then returned or deleted. See our GDPR statement.
08Who else sees it
We do not sell personal data, and we do not share it for anyone else's marketing. We do rely on a small number of service providers, who act on our instructions:
- Email and productivity
- Hosted email and document services used to receive and answer correspondence.
- Infrastructure and hosting
- The cloud and hosting providers that run this website and our working environments.
- Accounting and payments
- Our accountants and bookkeeping software, for invoicing and statutory accounts.
- Professional advisers
- Lawyers, insurers and auditors, where they need it and are bound by confidentiality.
We will also disclose personal data where the law requires it, to a regulator or court, or to protect our rights, property or safety. If our business is sold or reorganised, records may transfer to the buyer under equivalent protections.
A current list of the specific providers we use is available on request.
09Sending data outside the UK
Some of our providers are based outside the UK, or store data outside it — most commonly in the United States or the European Economic Area.
Where that happens, we make sure one of these applies: the country has UK adequacy regulations (which includes the EEA and, for certified organisations, the UK Extension to the EU–US Data Privacy Framework); or the transfer is covered by the UK's International Data Transfer Agreement, or the EU Standard Contractual Clauses with the UK Addendum, together with a transfer risk assessment.
You can ask us for details of the safeguards used for any particular transfer.
10Your rights
Under the UK GDPR you have the right to:
- Access — get a copy of the personal data we hold about you;
- Rectification — have inaccurate or incomplete data corrected;
- Erasure — ask us to delete data, where there is no overriding reason to keep it;
- Restriction — ask us to pause processing while a question about it is resolved;
- Portability — receive data you gave us in a structured, machine-readable format;
- Object — object to processing based on legitimate interests, and to direct marketing at any time, which we will always honour;
- Withdraw consent — where we relied on consent, withdraw it at any time, without affecting what we did beforehand.
To exercise any of these, email us at hello ( at ) antcodelabs.ai. We will respond within one month, and will tell you if we need longer because the request is complex. There is no charge unless a request is manifestly unfounded or excessive. We may need to confirm your identity first.
11Complaints
If you think we have handled your personal data badly, please tell us first — most things are fixed quickly once we know about them.
You also have the right to complain to the Information Commissioner's Office, the UK's data protection regulator, at ico.org.uk or on 0303 123 1113. Complaining to us first does not affect that right.
12How we keep it safe
We use measures appropriate to the risk, including encryption in transit, access control on a need-to-know basis, multi-factor authentication on business accounts, managed secrets, encrypted devices, patching, and logging. Our GDPR statement describes these in more detail.
No system is perfectly secure. If a breach affects your personal data and is likely to result in a high risk to your rights and freedoms, we will tell you without undue delay, and will notify the ICO within 72 hours where the law requires it.
13Children
This site and our services are aimed at businesses. We do not knowingly collect personal data from children under 13. If you believe a child has sent us personal data, contact us and we will delete it.
14Changes to this policy
We may update this policy as our business or the law changes. The date at the top of the page shows when it last changed. Where a change materially affects how we handle your data, we will take reasonable steps to tell you.