Legal

Privacy Policy

How Neon Lace collects, uses and protects your data.

Neon Lace Ltd | Company Number: 16530125 | ICO Registration Number: ZC188343
Last updated: 1 August 2026

1. Who We Are

1.1 Data controller. Neon Lace Ltd ("Neon Lace," "we," "us") is the data controller responsible for your personal data. Neon Lace is registered in England and Wales under company number 16530125.

1.2 Contact. For any questions about this policy or your personal data, contact us at editor@neon-lace.com.

1.3 What this policy covers. This policy explains what personal data we collect, why we collect it, how we use it, who we share it with, how long we keep it, and what rights you have. It applies to all personal data collected through our website at neon-lace.co.uk and in connection with our services and research activities, including Guest Brief, Intelligence, The Edit, memberships, and digital products.

2. What We Collect and Why

We collect different categories of personal data depending on how you interact with us. The sections below set out what we collect, why, and the legal basis under UK GDPR.

2.1 Website visitors. (i) Data collected: technical data including IP address, browser type, pages visited, and time spent on site, collected automatically via Ghost's built-in analytics. (ii) Purpose: to understand how visitors use the site and to improve content and performance. (iii) Lawful basis: legitimate interest (website improvement and analytics).

2.2 The Edit — consultancy clients. (i) Data collected: name, email address, professional situation, responses to the intake form, intake call notes, session notes, and the written Intelligence Brief. (ii) Purpose: to assess your enquiry, prepare for and deliver the consultation, produce the Intelligence Brief, and follow up after the engagement. (iii) Lawful basis: contractual necessity (to deliver the service you have booked); legitimate interest (to improve our services and produce anonymised research).

2.3 Memberships (The Afterparty and The Upper Floor). (i) Data collected: name, email address, membership tier, and billing information processed via Stripe. (ii) Purpose: to manage your membership, deliver member content, and process payments. (iii) Lawful basis: contractual necessity (to deliver the membership you have purchased).

2.4 Digital product purchases. (i) Data collected: name, email address, product purchased, and billing information processed via Stripe. (ii) Purpose: to process your purchase and deliver the digital product. (iii) Lawful basis: contractual necessity (to fulfil your order).

2.5 Guest Brief — commissioned advisory engagements. (i) Data collected from commissioning clients: name, email address, business name, role, and project details shared during the Discovery Call and scoping process. (ii) Purpose: to scope, produce, and deliver the commissioned brief, manage the engagement, and process payments. (iii) Lawful basis: contractual necessity (to deliver the commissioned work). (iv) Data processed during research: see section 2.7 below.

Neon Lace produces Guest Briefs under two engagement models. Under the reactive model, a client commissions research following a Discovery Call. Under the proactive model, Neon Lace independently identifies an organisation as a research subject and conducts research at its own initiative; the resulting brief is offered to the organisation on completion. In both cases, the desk-based research methodology described in section 2.7 applies.

2.6 Intelligence — independent research and publications. Neon Lace independently produces original research, market intelligence reports, trend analysis, and strategic publications for broader distribution. This research is not commissioned by any client. (i) Data processed during research: see section 2.7 below. (ii) Purpose: to produce and publish independent research and intelligence products. (iii) Lawful basis: legitimate interest (original research, knowledge production, and business development).

2.7 Publicly available data used in research. Guest Brief and Intelligence research is conducted using a desk-based methodology that analyses publicly available sources, including published guest reviews, property websites, social media presence, and press coverage. This analysis may involve processing personal data that is already in the public domain, such as reviewer names, published opinions, and publicly visible professional information. (i) Purpose: to conduct research and analysis for Guest Brief and Intelligence outputs. All personal data processed during research is anonymised and aggregated before inclusion in any deliverable or publication; no individual is identifiable in the final output. (ii) Lawful basis: legitimate interest (original research and intelligence production). (iii) Transparency under Article 14 of UK GDPR: where personal data is obtained from publicly available sources rather than directly from the individual, we are required to be transparent about that processing. This policy serves as the primary transparency mechanism. It would involve disproportionate effort to contact each individual whose publicly available data is included in our research, within the meaning of Article 14(5)(b) of UK GDPR, given the volume and public nature of the data.

2.8 Business development and outreach. (i) Data collected: name, email address, role, organisation, interaction history, and qualification notes relating to prospective clients and business contacts. (ii) Purpose: to identify, qualify, and develop business relationships, manage outreach, and track opportunities. (iii) Lawful basis: legitimate interest (business development and client acquisition).

2.9 Contact and enquiries. (i) Data collected: name, email address, and the content of your message. (ii) Purpose: to respond to your enquiry. (iii) Lawful basis: legitimate interest (to respond to communications sent to us).

3. Anonymised Use of Insights

3.1 Neon Lace may use anonymised scenarios, patterns, and insights derived from Guest Brief engagements, Intelligence research, consultancy engagements, and client interactions for research, educational, or marketing purposes. No individual will be identifiable from this material.

3.2 If we ever wish to use your name, likeness, or identifiable details for a testimonial, case study, or marketing purpose, we will seek your written consent. If no response is received within 14 days, the request is treated as declined.

3.3 Lawful basis: legitimate interest (business development and knowledge sharing), with identifiable use subject to explicit consent.

4. Follow-Up Communications

4.1 The Edit clients. After your engagement, we may contact you to follow up on your experience and to let you know about similar services such as The Next Move or The Re-Edit. This is permitted under the Privacy and Electronic Communications Regulations 2003 (PECR) soft opt-in exemption, as the communication relates to similar services you have already used.

4.2 How to opt out. Every follow-up message includes a clear way to opt out. If you opt out, we will stop sending follow-up communications promptly and will not contact you for marketing purposes unless you give fresh consent. Opting out of follow-up communications does not affect the retention or deletion of your session data under this policy.

4.3 Newsletters. If we introduce a newsletter or mailing list in future, subscription will be based on your explicit consent. You will be able to unsubscribe at any time.

5. Who We Share Your Data With

5.1 We do not sell your personal data to anyone.

5.2 We share personal data only with trusted third-party service providers who process data on our behalf and under our instructions. These are:

  1. Ghost (Ghost Foundation, US) — website hosting, content delivery, and built-in analytics.
  2. Stripe (Stripe Inc., US) — secure payment processing for The Edit, memberships, and digital products.
  3. Calendly (Calendly LLC, US) — scheduling for The Edit intake calls and sessions.
  4. Whereby (Whereby AS, Norway) — secure video calls for The Edit consultations.

5.3 Where we engage contractors or freelancers to assist with services such as research support, editorial assistance, content production, or administrative tasks, those individuals may process personal data on our behalf. Each contractor who handles personal data is bound by a written agreement that includes data protection obligations equivalent to those we apply to our technology providers.

5.4 Each processor is contractually bound to handle your data in accordance with data protection law and only for the purposes we specify.

5.5 We may also disclose personal data where required to do so by law, regulation, or court order.

6. International Data Transfers

6.1 Some of our service providers — Ghost, Stripe, and Calendly — are based in the United States. Whereby is based in Norway, which is within the European Economic Area.

6.2 Where personal data is transferred outside the United Kingdom, we ensure that appropriate safeguards are in place, including Standard Contractual Clauses approved by the UK Government or reliance on a UK adequacy decision, in accordance with UK GDPR.

7. How Long We Keep Your Data

7.1 We retain personal data only for as long as necessary for the purpose it was collected. The periods below set out our retention periods.

  1. The Edit — intake form, call notes, session notes, and Intelligence Brief: 12 months from the date of the session, after which securely deleted unless you have booked a further engagement.
  2. The Edit — contact details for follow-up communications: up to 12 months from the session, unless you opt out sooner.
  3. Membership data: retained for the duration of your membership and deleted within 12 months of cancellation, except where financial records must be retained longer.
  4. Digital product purchase records: retained for the duration required to deliver the product and provide support, then deleted within 12 months, except where financial records must be retained longer.
  5. B2B intelligence brief engagement data: 12 months from completion of the brief, unless a longer retention period is agreed in the engagement terms.
  6. Pre-anonymisation research data: raw research materials collected from publicly available sources under section 2.7 are anonymised or securely deleted within 6 months of completion of the relevant deliverable or publication.
  7. Website analytics data: 12 months from the date of collection.
  8. Business development and outreach data: 24 months from the date of the last meaningful contact with the prospective client or business contact, after which the record is reviewed and deleted if no active relationship has developed.
  9. Financial and transaction records: retained for 6 years from the date of the transaction as required by HMRC for tax and accounting purposes.
  10. Contact and enquiry messages: 12 months from the date of your message.

7.2 When the retention period expires, personal data is securely deleted or anonymised so that it can no longer be linked to you.

8. Cookies

8.1 This site runs on Ghost, which uses a limited number of cookies that are strictly necessary for the website to function, such as remembering whether you are logged in as a member.

8.2 We do not currently use Google Analytics or any third-party tracking cookies beyond Ghost's built-in analytics, which collects anonymous usage data and does not use cookies to track individual visitors.

8.3 If we introduce additional analytics or tracking tools in future, we will update this policy and implement a cookie consent mechanism before any non-essential cookies are placed on your device.

8.4 You can manage cookies through your browser settings at any time.

9. AI and Personal Data

9.1 Neon Lace uses AI tools as part of its research and content production workflow. Full details of how AI is used, including editorial standards and safeguards, are set out on our AI Transparency page.

9.2 Where AI tools are used in connection with personal data — for example, to assist with organising or structuring content based on client information — this processing is carried out under the same lawful bases, security standards, and retention periods described in this policy. AI tools are used as production tools and are not given autonomous decision-making authority over personal data.

9.3 Where AI platform settings allow, we have disabled model training to prevent client information and business data from being used to train AI models. This applies to ChatGPT and Claude, where training opt-out settings are available and have been activated.

10. Your Rights

10.1 Under UK GDPR, you have the following rights in relation to your personal data:

  1. Right of access — to request a copy of the personal data we hold about you.
  2. Right to rectification — to request correction of inaccurate or incomplete data.
  3. Right to erasure — to request deletion of your data where there is no compelling reason for us to continue processing it.
  4. Right to restrict processing — to request that we limit how we use your data in certain circumstances.
  5. Right to data portability — to request a copy of your data in a structured, commonly used format.
  6. Right to object — to object to processing based on legitimate interest, including for marketing purposes.
  7. Right to withdraw consent — where processing is based on consent, you may withdraw it at any time without affecting the lawfulness of processing carried out before withdrawal.

10.2 To exercise any of these rights, email us at editor@neon-lace.com. We will respond within one month.

10.3 If you are not satisfied with how we handle your request, you have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk or by calling 0303 123 1113.

11. Children

11.1 Our services are not directed at individuals under the age of 18. We do not knowingly collect personal data from children. If you believe we have collected data from a child, please contact us at editor@neon-lace.com and we will delete it promptly.

12. Changes to This Policy

12.1 We may update this policy from time to time to reflect changes in our services, data practices, or legal requirements. The latest version will always be published at neon-lace.co.uk/privacy-policy with the date of the last update shown at the top.

12.2 Where changes are material, we will take reasonable steps to notify you, such as posting a notice on the website or emailing you directly where appropriate.

Neon Lace Ltd | Registered in England and Wales | Company Number: 16530125

Contact: editor@neon-lace.com

Privacy Policy