This Privacy Notice explains how Landytech Limited collects and uses your personal data when you visit www.landytech.com, contact us, sign up for our communications, or apply for a job through our website.
If you use the Sesame investment platform, the way we handle the data you process on that platform is explained in a separate notice.
We do not sell your personal data, we do not use your data to make solely automated decisions about you, and we ask for your consent before we use any non-essential cookies.
You have a number of rights over your personal data. To exercise any of them, or to ask us anything about how we handle your data, contact our Data Protection Officer at dpo-office@cranium.eu.
Landy Tech Limited, trading as Landytech (“Landytech”, “we”, “us”, “our”), is committed to protecting your personal data.
This Privacy Notice explains how we collect, use, share, store and protect personal data when you visit www.landytech.com or otherwise interact with us in a marketing, recruitment or general-enquiry context.
We process personal data in accordance with applicable data protection laws, including:
This Privacy Notice applies to the Landytech website and our general business activities. If you use our Sesame investment platform, there is a separate Sesame Privacy Notice that explains how data is handled on the platform itself.
Read the Cookie Notice and the Sesame Privacy Notice.
Landy Tech Limited is the controller responsible for personal data collected through this website and through our wider marketing and recruitment activities. Our details are:
We have offices in the United Kingdom, France (Paris) and India (Pune). Our Paris office serves as our principal establishment in the European Economic Area for the purposes of EU GDPR. We do not need to appoint an Article 27 EU GDPR representative because we have an EU establishment.
For the activities covered by this Privacy Notice (visiting our website, contacting us, marketing, events, recruitment), we are the controller of your personal data. This means we decide what data is collected, why, and how it is used.
When you access the Sesame investment platform as a user of an organisation that has subscribed to our services, we usually act as a data processor on behalf of that organisation. In that case, your employer (or the organisation that has given you access) is the controller of the personal data processed on the platform, and you should look at their privacy notice for information about how that data is used. The Sesame Privacy Notice explains how we handle data in our processor capacity.
This Privacy Notice applies to personal data we collect and process when you:
We collect different categories of personal data depending on how you interact with us.
Information that allows us to identify and contact you, including:
Sources: you, your employer, or publicly available professional sources. We may also obtain business contact information from third-party sales-intelligence providers (see section 5).
Information you provide when you make an enquiry with us, including your name, organisation, contact details, job title, and the content of your enquiry.
Where you create an account for any of our marketing services (for example, gated content downloads, event sign-ups, or our resource library), we process your account identifier, name, email address, organisation name, account creation and modification dates, preferences and marketing settings.
The content of communications between you and us, including emails, chat messages, telephone records (where calls are recorded with notice), correspondence records and the associated metadata (time, date, channel).
Information about how you use our website, including:
We collect usage data through cookies and similar technologies. Full details, including the categories of data each cookie collects and the providers involved, are in our Cookie Notice. We only set non-essential cookies (analytics, session recording, marketing) where you have given us your consent.
If you apply for a role with us, we process:
Some of the personal data we process is “special category data” under Article 9 UK GDPR — information about racial or ethnic origin, religious beliefs, health, sexual orientation, or trade-union membership, for example.
We only process special category data where one of the conditions in Article 9(2) UK GDPR and (where relevant) Schedule 1 of the Data Protection Act 2018 is met. In practice, the only times we process special category data are:
We maintain an appropriate policy document covering our processing of special category data, in line with Schedule 1 Part 4 Paragraph 39 of the Data Protection Act 2018. A copy is available on request from our DPO.
Where the role you have applied for involves a regulated activity or is otherwise subject to background checks (for example, roles in finance-adjacent functions), we may carry out a check that includes criminal-records information. We rely on Schedule 1 Part 2 of the Data Protection Act 2018 for this processing and only do so where it is necessary, proportionate and lawful. We will tell you in advance if such a check is required.
In a business-to-business context, we sometimes obtain professional contact information about you from third parties. This may include your name, job title, employer organisation and professional contact details.
The third-party sources we use include:
When we receive your personal data from a third party for the first time, we will provide you with this Privacy Notice (or a link to it) within a reasonable period — and in any case no later than one month — in line with Article 14(3) of the UK GDPR. Where we contact you directly, we will provide the notice in our first communication.
Under data protection law, we need a lawful basis for everything we do with your personal data. The table below summarises the main purposes for which we use personal data and the lawful basis that applies. The Article references are to the UK GDPR; the corresponding EU GDPR provisions are the same.
Website operations
Running this website and the services it offers, including hosting, performance, technical administration and putting visitors in touch with the right teams.
Lawful basis. Legitimate interests (Article 6(1)(f)) in operating and improving our website and business. Performance of a contract (Article 6(1)(b)) where you have entered into one with us.
Relationship management and communications
Communicating with you by email, phone, post or chat. Responding to enquiries. Providing support. Managing our customer, prospect and partner relationships.
Lawful basis. Legitimate interests (Article 6(1)(f)) in maintaining business relationships. Pre-contractual steps taken at your request (Article 6(1)(b)). Compliance with legal obligations (Article 6(1)(c)) where applicable.
Personalisation
Tailoring website content, offers and information to your role, industry and interests.
Lawful basis. Consent (Article 6(1)(a)) where personalisation relies on non-essential cookies or similar technologies. Legitimate interests (Article 6(1)(f)) for non-cookie personalisation. We do not use personalisation to make decisions that produce legal or similarly significant effects on you.
Direct marketing
Sending you information about our services, including emails, telephone calls and postal marketing in a business-to-business context.
Lawful basis. Legitimate interests (Article 6(1)(f)) in promoting our services to relevant business contacts. Consent (Article 6(1)(a)) where consent is required by PECR or equivalent rules. You can object to direct marketing at any time (Article 21(2)) and we will stop.
Research and analytics
Understanding how visitors find and use our website so we can improve it.
Lawful basis. Consent (Article 6(1)(a)) where this involves non-essential cookies or similar technologies. Legitimate interests (Article 6(1)(f)) for non-cookie analysis of aggregated data.
Security and fraud prevention
Protecting our website, systems and users from malicious activity, unauthorised access and fraud.
Lawful basis. Legitimate interests (Article 6(1)(f)) in protecting our business and users. Compliance with legal obligations (Article 6(1)(c)).
Recruitment
Assessing your application for a role with us, communicating with you, conducting interviews and any pre-employment checks, and (if you join us) onboarding you.
Lawful basis. Pre-contractual steps at your request (Article 6(1)(b)). Legitimate interests (Article 6(1)(f)) in administering recruitment. Compliance with legal obligations (Article 6(1)(c)). For special-category and criminal-records data, see section 4 above.
Record-keeping, insurance, professional advice
Maintaining our business records, obtaining or maintaining insurance, and taking professional advice.
Lawful basis. Legitimate interests (Article 6(1)(f)) in running our business properly. Compliance with legal obligations (Article 6(1)(c)) for statutory record-keeping.
Establishment, exercise or defence of legal claims
Using your personal data to take or defend legal action, or to resolve disputes.
Lawful basis. Legitimate interests (Article 6(1)(f)) and compliance with legal obligations (Article 6(1)(c)). For special category data, Article 9(2)(f).
Where we rely on legitimate interests, we have weighed those interests against your rights. You can ask us for a copy of our legitimate interests assessment by contacting our DPO.
We may share your personal data with:
Where third parties process personal data on our behalf, we put in place written agreements that meet the requirements of Article 28 of the UK GDPR (and Article 28 of the EU GDPR where applicable).
Our Cookie Notice lists the specific third-party providers whose cookies and tags are present on our website.
Some of our service providers are located outside the United Kingdom and the European Economic Area, in particular in the United States and India (where our Pune office is located).
When we transfer personal data outside the United Kingdom or the European Economic Area, we make sure that an appropriate safeguard is in place. The safeguards we rely on include:
For transfers to India and other countries that are not covered by an adequacy decision, we carry out a Transfer Risk Assessment in line with guidance from the Information Commissioner's Office (ICO) and the European Data Protection Board (EDPB), and we put in place additional technical, contractual and organisational measures where necessary.
You can request more information about the safeguards we use, or for a copy of the relevant standard contractual clauses or transfer agreements, by contacting our DPO at dpo-office@cranium.eu.
We keep your personal data only for as long as we need it for the purposes for which we collected it, including to satisfy any legal, regulatory, tax, accounting or reporting requirements.
Our typical retention periods are:
| Category of data | Typical retention period |
|---|---|
| Enquiry data (general website enquiries) | Up to 24 months from your last interaction with us |
| Marketing data (B2B contact records and engagement history) | Until you opt out, or up to 24 months of inactivity, whichever is sooner |
| Recruitment data — unsuccessful candidates | Up to 12 months after the end of the recruitment process, unless you ask us to delete it sooner or to keep it longer for future opportunities |
| Recruitment data — successful candidates | Transferred to your employee file on hiring and retained in line with our employee records retention policy |
| Account data (marketing-services accounts) | Duration of the account plus up to 6 years for legal limitation purposes |
| Website analytics and cookie data | As set out in our Cookie Notice. Google Analytics cookies are typically retained for up to 13 months, and Google Analytics event data for up to 14 months (the GA4 default maximum). Hotjar session-user cookies are retained for up to 13 months. Microsoft Clarity identifiers are retained for up to 16 months. |
| Communications (emails, chat transcripts) | Up to 6 years for legal limitation purposes |
| Special category data (equal-opportunities monitoring) | Held separately from application files; deleted or aggregated within 12 months |
| Records required by law (tax, accounting, audit) | As required by the relevant statutory regime, typically 6 to 7 years |
We may keep personal data for longer where there is a legal or regulatory reason to do so, where there is an ongoing dispute, or where we need it to establish, exercise or defend legal claims. Once the retention period has ended, we delete or anonymise the personal data.
We do not use solely automated decision-making (decisions made without meaningful human involvement) to make decisions about you that produce legal effects or similarly significantly affect you, in the sense of Article 22 UK GDPR.
We do use some profiling for marketing personalisation — for example, we may tailor the content of our emails or website to your industry or job role based on what you have told us or what you have viewed. This profiling does not produce legal or similarly significant effects, and you can object to it at any time using the contact details in section 13.
Some of our products include AI-based features (for example, the Sesame aLi agent). The Sesame Privacy Notice explains how those features handle personal data on the platform.
You have a number of rights over your personal data under the UK GDPR and (where it applies) the EU GDPR. They include:
You can exercise any of your rights free of charge by contacting our DPO using the details in section 13. We may need to verify your identity before responding, particularly where the request involves sensitive data.
We will normally respond within one month of receiving your request. Where a request is particularly complex, or where you have made several requests, we may extend this by up to a further two months, in which case we will tell you within the first month and explain why.
Where a request is manifestly unfounded or excessive, we may charge a reasonable fee or refuse to act on it. We will explain our reasoning if this is ever the case.
If you are unhappy with how we handle your personal data, please contact us first so that we can try to resolve the issue. You can also lodge a complaint with a data protection supervisory authority.
In the United Kingdom, the supervisory authority is the Information Commissioner's Office:
If you are in the European Economic Area, you can lodge a complaint with your local data protection authority. A list of national authorities is available on the European Data Protection Board's website at EDPB list of national authorities. This includes the Commission nationale de l'informatique et des libertés (CNIL) in France, where our Paris office is located.
Our website and services are not intended for children. We do not knowingly collect personal data from anyone under the age of 16. If you believe a person under 16 has provided us with personal data, please contact us and we will take steps to delete it.
Our website contains links to third-party websites, including social-media platforms. We are not responsible for the privacy practices of those websites or platforms. We encourage you to read their privacy notices before sharing any personal data with them.
We review this Privacy Notice regularly, and update it whenever the way we handle personal data changes in a material way. When we make changes, we update the version number and the date at the top of this notice. Where the changes are significant, we will tell you in a more prominent way (for example, by email or by displaying a banner on our website).
Email: privacy@landytech.com
Post: Landy Tech Limited, 52A Cromwell Road, London, SW7 5BE, United Kingdom
Our external Data Protection Officer can be contacted directly. You are welcome to contact the DPO instead of, or in addition to, our general privacy team.
Email: dpo-office@cranium.eu
Post: CRANIUM SA – DPO Office Landytech, Excelsiorlaan 43, 1930 Zaventem, Belgium