Privacy Policy
This Privacy Policy explains how Voholabs Ltd ("Voholabs", "we", "us") collects and processes personal data as a data controller under the UK General Data Protection Regulation ("UK GDPR") and the Data Protection Act 2018.
1. Identity of the controller
1.1 The data controller is Voholabs Ltd, a company incorporated in England and Wales. You can contact us at [email protected].
1.2 We have not appointed a statutory Data Protection Officer because we are not required to. Data protection enquiries should be addressed to [email protected].
2. Definitions
2.1 "Personal data", "processing", "controller", "processor", "data subject", and "special category data" have the meanings given in the UK GDPR.
2.2 "Services" means the services described in our Terms of Service, including private AI workshops, Deploy AI consulting blueprints, the Apex content automation agent, the free skills library, and Digital Bundles.
2.3 "Site" means voholabs.com.
2.4 "Platform" or "Platforms" means the third-party services that you authorise us to connect to on your behalf, including Google (and Google APIs and services such as Search Console, Business Profile, YouTube, and Google Ads accounts where you connect them), LinkedIn, Meta Platforms (Facebook and Instagram), and X (formerly Twitter). "Platform Data" means the data we access from a Platform under your authorisation.
3. Categories of personal data we collect
3.1 Information you provide. Name, business email address, employer or business name, job role, LinkedIn URL, telephone number (where supplied), and information you submit through forms (including the bundle studio, workshop booking forms, consulting enquiries, and Apex onboarding intake), such as a description of your work, goals, brand assets, and content preferences.
3.2 Account and access information for Apex. Where you engage Apex, the credentials, API keys, OAuth tokens, account identifiers, and permissions you grant us so the agent can publish, schedule, or post content on your behalf. We never store credentials in plain text and only use them for the configured purpose.
3.3 Platform Data. Where you connect a Platform (see section 8), we access data made available through that Platform under the scopes and permissions you approve. This is described in detail in section 8.
3.4 Transaction information. Order details, invoice information, billing address, VAT details, and payment confirmation data (we do not store full payment card numbers; these are handled by Stripe).
3.5 Correspondence. The content of emails, calendar invitations, and messages you send us and our replies.
3.6 Workshop participation data. Attendance, contributions, and (with your prior notice and where applicable consent) recordings of the live sessions you attend.
3.7 Technical data. IP address, device and browser type, operating system, referrer, pages requested, timestamps, and basic server logs collected automatically when you use the Site.
3.8 Special category data. We do not ask for and do not knowingly process special category data (such as health, racial or ethnic origin, political opinions, religious beliefs, trade union membership, genetic, biometric, sex life, or sexual orientation data). Please do not send it to us.
4. Purposes of processing and lawful bases
4.1 We process personal data only where we have a lawful basis under Article 6 UK GDPR. The clauses below set out, for each processing activity, the purpose and the lawful basis we rely on.
4.2 Providing the Services and performing contracts. We process your name, business contact details, Order information, and any content or instructions you supply in order to perform our contract with you (or to take steps at your request prior to entering into a contract). Lawful basis: Article 6(1)(b) (performance of a contract).
4.3 Running Apex on your behalf. We process the credentials, content briefs, brand assets, publishing instructions, and Platform Data you supply or authorise, and we transmit those to Third-Party AI Platforms and to the Platforms where content is published, in order to deliver Apex. Lawful basis: Article 6(1)(b) (performance of a contract). Where Apex processes personal data of your contacts or audience, you are the controller and we act as your processor under a data processing agreement; the lawful basis for that processing must be established by you.
4.4 Bundle studio, lead capture, and follow-up. When you submit the bundle studio or another lead form, we use your details to generate and deliver the requested materials and to follow up. Lawful basis: Article 6(1)(b) where you have requested deliverables; Article 6(1)(a) (consent) for follow-up communications that constitute electronic direct marketing under PECR; and Article 6(1)(f) (legitimate interests) for record-keeping and limited business-to-business follow-up, where our interest in delivering and improving the Services is balanced against your rights.
4.5 Workshop and cohort administration. Scheduling sessions, issuing joining instructions, managing attendance, providing recordings (where applicable), and post-cohort follow-up. Lawful basis: Article 6(1)(b) (performance of a contract).
4.6 Payments and finance. Processing payments, issuing invoices and credit notes, managing refunds and chargebacks, and keeping financial records. Lawful basis: Article 6(1)(b) (performance of a contract) and Article 6(1)(c) (legal obligation under UK tax and accounting law).
4.7 Security, fraud prevention, and Site operation. Maintaining logs, preventing abuse, securing accounts and content, and operating the Site. Lawful basis: Article 6(1)(f) (legitimate interests in operating a secure service).
4.8 Improving the Services. Analysing anonymised or aggregated usage patterns to improve the skills library, workshop content, and Apex. Lawful basis: Article 6(1)(f) (legitimate interests in improving our offering).
4.9 Marketing emails. Sending occasional emails about our skills library, cohorts, and new services. Lawful basis: Article 6(1)(a) (consent), supplemented by the soft opt-in under Regulation 22(3) of the Privacy and Electronic Communications (EC Directive) Regulations 2003 ("PECR") where it applies, and Article 6(1)(f) (legitimate interests) for limited business-to-business postal or corporate-address communications.
4.10 Legal claims and compliance. Establishing, exercising, or defending legal claims, complying with court orders, regulator requests, and our legal obligations. Lawful basis: Article 6(1)(c) (legal obligation) and Article 6(1)(f) (legitimate interests in protecting our rights).
5. Sources of personal data
5.1 We obtain personal data directly from you (forms, emails, payment, and onboarding) and, where you engage Apex, from the Platforms and accounts you connect (for example, the Google, LinkedIn, Meta, X, analytics, or CMS accounts you authorise us to access). We only obtain Platform Data through the authorisation flows and permissions you approve.
5.2 We do not buy marketing lists.
6. Recipients and categories of recipient
6.1 We share personal data with the following categories of recipient, only as necessary for the purposes described in section 4 and under appropriate contractual protections:
- Hosting and infrastructure providers for the Site, application logs, and backups (e.g. cloud hosting and content delivery providers).
- Form, scheduling, and CRM providers used to capture submissions, book sessions, and manage client relationships (e.g. Typeform or similar form providers, calendar providers, customer relationship management tools).
- Email and communication providers used to send transactional and (where consented) marketing emails (e.g. email service providers).
- Video conferencing providers used to deliver live workshops (e.g. Zoom, Google Meet, or similar).
- Payment providers, principally Stripe, who act as independent controller for fraud prevention and as our processor for payment execution.
- Accounting, bookkeeping, and tax providers, including our accountants and HMRC where required by law.
- Professional advisers, including legal and insurance advisers, where reasonably necessary.
- Third-Party AI Platforms (see section 7).
- Platforms you connect (Google, LinkedIn, Meta Platforms, X, and other publishing or analytics platforms) that you authorise us, through Apex, to access or post content to on your behalf (see section 8).
- Regulators, courts, and law enforcement where we are required to disclose information by law.
- Successors and acquirers, where we sell or transfer all or part of our business, subject to appropriate confidentiality obligations.
6.2 We do not sell personal data and do not share it for the independent direct marketing purposes of third parties.
7. AI sub-processors
7.1 The Services rely on third-party artificial intelligence platforms to generate, analyse, classify, schedule, and publish content. These platforms act as our sub-processors when processing personal data on our behalf (or, where applicable, as independent controllers under their own terms).
7.2 Current Third-Party AI Platforms include providers such as OpenAI, Anthropic, Google, Microsoft, and similar providers. The list may change over time as platforms are added or replaced. A current list is available on request from [email protected].
7.3 Content and instructions submitted to these platforms may be processed outside the United Kingdom (see section 9). We rely on each provider's contractual commitments not to use customer content to train general-purpose models without authorisation, but we cannot guarantee the practices of any third party. Please do not submit personal data to the Services that you would not want transmitted to a Third-Party AI Platform. For the avoidance of doubt, we do not use Platform Data obtained from Google, LinkedIn, Meta Platforms, or X to train general-purpose AI models (see section 8).
8. Platform integrations and third-party Platform Data
8.1 Where you use Apex or a related integration, you may authorise us to connect to third-party Platforms, including Google (and Google APIs and services such as Search Console, Business Profile, YouTube, and Google Ads accounts where you connect them), LinkedIn, Meta Platforms (Facebook and Instagram), and X (formerly Twitter). We only connect to a Platform after you complete that Platform's authorisation flow (for example, OAuth) and grant the requested permissions. You can review and revoke these permissions at any time (see section 8.9 and section 16).
8.2 Platform Data we access. Depending on the Platform and the scopes you approve, Platform Data may include: OAuth or API tokens and refresh tokens; account, page, channel, and profile identifiers; profile, page, or account information; the permissions and scopes you grant; posts, drafts, and other content; media (images and video); comments, messages, and engagement metrics (such as likes, shares, views, and follower counts); analytics, insights, search, and webmaster data; publication and scheduling status; and technical logs relating to these operations. We only access the categories of Platform Data that you authorise us to access, and only to the extent the granted scopes allow.
8.3 How we use Platform Data. We access and use Platform Data solely to: (a) provide the user-facing content publishing, scheduling, social, and analytics functionality that you or the Client request through Apex and the Services; (b) maintain the security and integrity of the Services and prevent abuse; (c) debug, troubleshoot, and provide support; (d) comply with applicable law and lawful requests; and (e) improve and maintain the Services using aggregated or anonymised data that does not identify you or any individual. Our access to and use of Google user data conforms to the Google API Services User Data Policy, including the Limited Use requirements. Our access to, use of, storage of, and disclosure of LinkedIn, Meta Platforms, and X data likewise complies with each Platform's developer terms, API terms, and data restrictions.
8.4 No sale of Platform Data. We do not sell Platform Data.
8.5 No advertising or profiling use. We do not use Platform Data for third-party advertising, retargeting, ad networks, credit-worthiness assessment, lending decisions, data brokerage, or profiling that is unrelated to the functionality you requested.
8.6 No AI model training. We do not use Google, LinkedIn, Meta Platforms, or X Platform Data to develop, train, or improve general-purpose or foundational artificial intelligence or machine learning models. Where AI is used to perform functionality you requested (for example, drafting or classifying your own content), it is used only for that purpose and subject to the AI provider commitments described in section 7.
8.7 Human access. Human access to Platform Data is limited to staff and contractors who need access to: provide support you have requested; troubleshoot or debug an issue; secure the Services and investigate abuse or security incidents; comply with applicable law; review specific content or account data where the Client asks us to; or handle data in aggregated or anonymised form for internal operations. Access is subject to confidentiality obligations and role-based access controls.
8.8 Disclosure of Platform Data. We share Platform Data only with: (a) the processors and sub-processors we use to deliver the Services (for example, hosting, infrastructure, and content systems), under contractual protections; (b) the relevant Platform itself, in order to perform the actions you requested; (c) Third-Party AI Platforms and content systems where necessary to perform the specific functionality you requested (see section 7); (d) regulators, courts, and law enforcement where required by law; and (e) a successor or acquirer of our business, subject to appropriate confidentiality and data protection safeguards. We do not otherwise transfer Platform Data to third parties, and we do not make Platform Data available for the independent purposes of others.
8.9 Revoking access. You or the Client can revoke our OAuth or API access at any time through the relevant Platform's settings (for example, your Google Account, LinkedIn, Meta, or X app or connected-apps settings), and you can request deletion of Platform Data by emailing [email protected] (see section 16). Revoking access may stop the affected functionality from working.
8.10 Deletion and retention of Platform Data. On termination of the engagement, revocation of access, or a deletion request, we delete or anonymise the associated Platform Data (including stored tokens) without undue delay, unless and only to the extent retention is required for legal, security, billing, dispute-resolution, or regulatory compliance reasons, in which case we retain only what is necessary and for no longer than necessary.
9. International transfers
9.1 Some recipients listed above are located outside the United Kingdom, including in the United States and the European Economic Area.
9.2 Where we transfer personal data outside the United Kingdom, we rely on one of the following safeguards: (a) an adequacy regulation made by the Secretary of State under section 17A of the Data Protection Act 2018 (e.g. the UK's adequacy regulations covering EEA countries and, in respect of certified US recipients, the UK Extension to the EU-US Data Privacy Framework); (b) the UK International Data Transfer Agreement ("UK IDTA"); (c) the UK Addendum to the European Commission's Standard Contractual Clauses; or (d) another lawful transfer mechanism under Article 46 UK GDPR.
9.3 A copy of the relevant safeguard documentation is available on request from [email protected].
10. Retention
10.1 We keep personal data only for as long as necessary for the purposes for which it was collected, including for satisfying any legal, accounting, or reporting requirements. The retention periods below are guidance; we will keep data for shorter periods where reasonably possible.
- Lead and bundle studio submissions: up to 24 months from your last interaction, then deleted or anonymised.
- Client and contract records (including engagement letters and Order confirmations): the duration of the engagement plus 6 years to meet limitation periods under English law.
- Financial, tax, and VAT records: 6 years from the end of the relevant accounting period, in line with HMRC requirements.
- Workshop attendance and recordings: recordings kept for up to 12 months unless agreed otherwise in writing.
- Apex configurations, content history, and audit logs: the duration of the engagement plus 24 months to support troubleshooting and dispute handling.
- Platform Data and Platform tokens: for the duration of the connection; deleted or anonymised on termination, revocation, or a deletion request, subject to section 8.10.
- Marketing consent records: for the duration of consent plus 24 months after withdrawal, to evidence the consent.
- Email correspondence: while reasonably needed for the relationship and then deleted on request or when no longer needed.
- Site server logs: typically up to 90 days, longer where required for security investigations.
10.2 Where data is no longer required, we delete or anonymise it.
11. Cookies and similar technologies
11.1 The Site uses only strictly necessary cookies and equivalent technologies needed to deliver the Site (for example, to balance load, secure forms, and remember essential session state). Strictly necessary cookies are exempt from the consent requirement in Regulation 6 PECR.
11.2 We do not currently use Google Analytics, advertising pixels, social-sharing tracking pixels, or other non-essential cookies. Previously deployed analytics tracking has been removed.
11.3 If we introduce non-essential cookies in future, we will request your consent through a compliant cookie banner before any such cookie is set, and we will update this Privacy Policy.
12. Marketing communications
12.1 We will only send you electronic marketing communications where you have consented or where the PECR soft opt-in applies (in which case we will rely on the soft opt-in only for similar Services and only after we have given you a clear opportunity to opt out at the point of collection).
12.2 You can withdraw consent and opt out at any time by clicking the unsubscribe link in any marketing email or by emailing [email protected].
13. Automated decision-making and profiling
13.1 We do not make decisions about you that produce legal or similarly significant effects on you and are based solely on automated processing.
13.2 AI is used in the Services to generate, classify, rank, and schedule content. Editorial review and final publishing decisions for AI Outputs are the responsibility of the Client as publisher of record under the Terms of Service.
14. Security
14.1 We use appropriate technical and organisational measures to protect personal data against unauthorised or unlawful processing, accidental loss, destruction, or damage, including encryption in transit, access controls, secret management for credentials and Platform tokens, role-based access to client data, and provider due diligence.
14.2 No system is perfectly secure. In the unlikely event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the Information Commissioner's Office within 72 hours of becoming aware and, where required, notify you without undue delay.
15. Your rights
15.1 Subject to the conditions set out in the UK GDPR, you have the following rights in respect of your personal data:
- Right of access (Article 15): to receive confirmation of whether we process your data and a copy of that data.
- Right to rectification (Article 16): to ask us to correct inaccurate or incomplete data.
- Right to erasure (Article 17): to ask us to delete your data in the circumstances set out in the UK GDPR.
- Right to restriction (Article 18): to ask us to limit processing in certain circumstances.
- Right to data portability (Article 20): to receive data you have provided to us in a structured, commonly used, machine-readable format, where the processing is based on consent or contract and is carried out by automated means.
- Right to object (Article 21): to object to processing based on legitimate interests, including profiling, and an absolute right to object to direct marketing.
- Right to withdraw consent (Article 7(3)): to withdraw your consent at any time, without affecting the lawfulness of processing before the withdrawal.
- Rights in relation to automated decision-making (Article 22): not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects (see section 13).
15.2 To exercise any of these rights, email [email protected]. We may need to verify your identity. We will respond within one month of receiving your request, which we may extend by a further two months for complex requests.
15.3 You will not have to pay a fee unless your request is manifestly unfounded, repetitive, or excessive, in which case we may charge a reasonable fee or refuse the request and explain why.
16. Data deletion and revoking Platform access
16.1 How to request deletion. You can ask us to delete your personal data and any connected Platform Data at any time. Email [email protected] with the subject line "Data deletion request", and identify the account and the Platform(s) concerned (for example, your Google, LinkedIn, Facebook, Instagram, or X account). We may need to verify your identity before acting on the request.
16.2 What we do. On a valid deletion request we will delete or anonymise the relevant personal data and Platform Data (including stored OAuth or API tokens) without undue delay, and in any event within the timeframe required by the UK GDPR (normally within one month, extendable by up to two further months for complex requests). We retain data only where and to the extent we are permitted or required to for legal, security, billing, dispute-resolution, or regulatory compliance reasons, as described in sections 8.10 and 10.
16.3 Revoking app permissions yourself. You can also revoke our access directly in your Platform account settings at any time, for example through the connected-apps or app-permissions controls in your Google Account, LinkedIn, Meta (Facebook and Instagram), or X settings. Revoking access stops further data access and will also stop the affected functionality from working.
17. Children
17.1 The Services are directed at working professionals. We do not knowingly collect personal data of children under 16. If you believe a child has provided personal data to us, please contact us and we will delete it.
18. Changes to this policy
18.1 We may update this Privacy Policy from time to time. The "Last updated" date at the top of this page indicates when it was last revised. Material changes will be highlighted on the Site and, where appropriate, notified to clients by email.
19. Complaints to the regulator
19.1 If you are not satisfied with our handling of your personal data, please contact us first so we can try to resolve your concern. You also have the right to lodge a complaint with the UK Information Commissioner's Office (the "ICO"):
- Website: https://ico.org.uk
- Helpline: 0303 123 1113
- Address: Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF, United Kingdom.
20. Contact
20.1 Privacy enquiries, rights requests, deletion requests, and complaints should be sent to [email protected]. We aim to acknowledge requests within 5 working days.
See also our Terms of Service and Refund Policy.