Legal
How Neon Lace collects, uses and protects your data.
1.1 Data controller. Neon Lace Ltd ("Neon Lace," "we," "us") is the data controller responsible for your personal data. Neon Lace is registered in England and Wales under company number 16530125.
1.2 Contact. For any questions about this policy or your personal data, contact us at editor@neon-lace.com.
1.3 What this policy covers. This policy explains what personal data we collect, why we collect it, how we use it, who we share it with, how long we keep it, and what rights you have. It applies to all personal data collected through our website at neon-lace.co.uk and in connection with our services and research activities, including Guest Brief, Intelligence, The Edit, memberships, and digital products.
We collect different categories of personal data depending on how you interact with us. The sections below set out what we collect, why, and the legal basis under UK GDPR.
2.1 Website visitors. (i) Data collected: technical data including IP address, browser type, pages visited, and time spent on site, collected automatically via Ghost's built-in analytics. (ii) Purpose: to understand how visitors use the site and to improve content and performance. (iii) Lawful basis: legitimate interest (website improvement and analytics).
2.2 The Edit — consultancy clients. (i) Data collected: name, email address, professional situation, responses to the intake form, intake call notes, session notes, and the written Intelligence Brief. (ii) Purpose: to assess your enquiry, prepare for and deliver the consultation, produce the Intelligence Brief, and follow up after the engagement. (iii) Lawful basis: contractual necessity (to deliver the service you have booked); legitimate interest (to improve our services and produce anonymised research).
2.3 Memberships (The Afterparty and The Upper Floor). (i) Data collected: name, email address, membership tier, and billing information processed via Stripe. (ii) Purpose: to manage your membership, deliver member content, and process payments. (iii) Lawful basis: contractual necessity (to deliver the membership you have purchased).
2.4 Digital product purchases. (i) Data collected: name, email address, product purchased, and billing information processed via Stripe. (ii) Purpose: to process your purchase and deliver the digital product. (iii) Lawful basis: contractual necessity (to fulfil your order).
2.5 Guest Brief — commissioned advisory engagements. (i) Data collected from commissioning clients: name, email address, business name, role, and project details shared during the Discovery Call and scoping process. (ii) Purpose: to scope, produce, and deliver the commissioned brief, manage the engagement, and process payments. (iii) Lawful basis: contractual necessity (to deliver the commissioned work). (iv) Data processed during research: see section 2.7 below.
Neon Lace produces Guest Briefs under two engagement models. Under the reactive model, a client commissions research following a Discovery Call. Under the proactive model, Neon Lace independently identifies an organisation as a research subject and conducts research at its own initiative; the resulting brief is offered to the organisation on completion. In both cases, the desk-based research methodology described in section 2.7 applies.
2.6 Intelligence — independent research and publications. Neon Lace independently produces original research, market intelligence reports, trend analysis, and strategic publications for broader distribution. This research is not commissioned by any client. (i) Data processed during research: see section 2.7 below. (ii) Purpose: to produce and publish independent research and intelligence products. (iii) Lawful basis: legitimate interest (original research, knowledge production, and business development).
2.7 Publicly available data used in research. Guest Brief and Intelligence research is conducted using a desk-based methodology that analyses publicly available sources, including published guest reviews, property websites, social media presence, and press coverage. This analysis may involve processing personal data that is already in the public domain, such as reviewer names, published opinions, and publicly visible professional information. (i) Purpose: to conduct research and analysis for Guest Brief and Intelligence outputs. All personal data processed during research is anonymised and aggregated before inclusion in any deliverable or publication; no individual is identifiable in the final output. (ii) Lawful basis: legitimate interest (original research and intelligence production). (iii) Transparency under Article 14 of UK GDPR: where personal data is obtained from publicly available sources rather than directly from the individual, we are required to be transparent about that processing. This policy serves as the primary transparency mechanism. It would involve disproportionate effort to contact each individual whose publicly available data is included in our research, within the meaning of Article 14(5)(b) of UK GDPR, given the volume and public nature of the data.
2.8 Business development and outreach. (i) Data collected: name, email address, role, organisation, interaction history, and qualification notes relating to prospective clients and business contacts. (ii) Purpose: to identify, qualify, and develop business relationships, manage outreach, and track opportunities. (iii) Lawful basis: legitimate interest (business development and client acquisition).
2.9 Contact and enquiries. (i) Data collected: name, email address, and the content of your message. (ii) Purpose: to respond to your enquiry. (iii) Lawful basis: legitimate interest (to respond to communications sent to us).
3.1 Neon Lace may use anonymised scenarios, patterns, and insights derived from Guest Brief engagements, Intelligence research, consultancy engagements, and client interactions for research, educational, or marketing purposes. No individual will be identifiable from this material.
3.2 If we ever wish to use your name, likeness, or identifiable details for a testimonial, case study, or marketing purpose, we will seek your written consent. If no response is received within 14 days, the request is treated as declined.
3.3 Lawful basis: legitimate interest (business development and knowledge sharing), with identifiable use subject to explicit consent.
4.1 The Edit clients. After your engagement, we may contact you to follow up on your experience and to let you know about similar services such as The Next Move or The Re-Edit. This is permitted under the Privacy and Electronic Communications Regulations 2003 (PECR) soft opt-in exemption, as the communication relates to similar services you have already used.
4.2 How to opt out. Every follow-up message includes a clear way to opt out. If you opt out, we will stop sending follow-up communications promptly and will not contact you for marketing purposes unless you give fresh consent. Opting out of follow-up communications does not affect the retention or deletion of your session data under this policy.
4.3 Newsletters. If we introduce a newsletter or mailing list in future, subscription will be based on your explicit consent. You will be able to unsubscribe at any time.
5.1 We do not sell your personal data to anyone.
5.2 We share personal data only with trusted third-party service providers who process data on our behalf and under our instructions. These are:
5.3 Where we engage contractors or freelancers to assist with services such as research support, editorial assistance, content production, or administrative tasks, those individuals may process personal data on our behalf. Each contractor who handles personal data is bound by a written agreement that includes data protection obligations equivalent to those we apply to our technology providers.
5.4 Each processor is contractually bound to handle your data in accordance with data protection law and only for the purposes we specify.
5.5 We may also disclose personal data where required to do so by law, regulation, or court order.
6.1 Some of our service providers — Ghost, Stripe, and Calendly — are based in the United States. Whereby is based in Norway, which is within the European Economic Area.
6.2 Where personal data is transferred outside the United Kingdom, we ensure that appropriate safeguards are in place, including Standard Contractual Clauses approved by the UK Government or reliance on a UK adequacy decision, in accordance with UK GDPR.
7.1 We retain personal data only for as long as necessary for the purpose it was collected. The periods below set out our retention periods.
7.2 When the retention period expires, personal data is securely deleted or anonymised so that it can no longer be linked to you.
8.1 This site runs on Ghost, which uses a limited number of cookies that are strictly necessary for the website to function, such as remembering whether you are logged in as a member.
8.2 We do not currently use Google Analytics or any third-party tracking cookies beyond Ghost's built-in analytics, which collects anonymous usage data and does not use cookies to track individual visitors.
8.3 If we introduce additional analytics or tracking tools in future, we will update this policy and implement a cookie consent mechanism before any non-essential cookies are placed on your device.
8.4 You can manage cookies through your browser settings at any time.
9.1 Neon Lace uses AI tools as part of its research and content production workflow. Full details of how AI is used, including editorial standards and safeguards, are set out on our AI Transparency page.
9.2 Where AI tools are used in connection with personal data — for example, to assist with organising or structuring content based on client information — this processing is carried out under the same lawful bases, security standards, and retention periods described in this policy. AI tools are used as production tools and are not given autonomous decision-making authority over personal data.
9.3 Where AI platform settings allow, we have disabled model training to prevent client information and business data from being used to train AI models. This applies to ChatGPT and Claude, where training opt-out settings are available and have been activated.
10.1 Under UK GDPR, you have the following rights in relation to your personal data:
10.2 To exercise any of these rights, email us at editor@neon-lace.com. We will respond within one month.
10.3 If you are not satisfied with how we handle your request, you have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk or by calling 0303 123 1113.
11.1 Our services are not directed at individuals under the age of 18. We do not knowingly collect personal data from children. If you believe we have collected data from a child, please contact us at editor@neon-lace.com and we will delete it promptly.
12.1 We may update this policy from time to time to reflect changes in our services, data practices, or legal requirements. The latest version will always be published at neon-lace.co.uk/privacy-policy with the date of the last update shown at the top.
12.2 Where changes are material, we will take reasonable steps to notify you, such as posting a notice on the website or emailing you directly where appropriate.
Neon Lace Ltd | Registered in England and Wales | Company Number: 16530125
Contact: editor@neon-lace.com