Privacy Policy

Last updated: 30 June 2026

This Privacy Policy explains how LabFabric (“LabFabric”, “we”, “us” or “our”) collects, uses, and protects your personal data when you use our lab-booking service (the “Service”). We are the data controller for the personal data described here. We comply with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

1. Data we collect

  • Account and booking data: your name, email address, and the details of the sessions and labs you book.
  • Payment data: payments are handled by Stripe. We receive confirmation of payment and limited transaction details (such as a payment reference); we do not receive or store your full card number.
  • Communications: messages you send us, for example through our contact or support forms.
  • Technical and usage data: limited information needed to operate the Service and keep it secure, such as session identifiers, access logs, and basic device or browser information.
  • Optional inputs: interest-registration and topic-poll responses, if you choose to submit them.

2. Lab connectivity via the Cloudflare One Client (WARP)

One of the ways you can connect to your booked lab is Cloudflare’s native client, the Cloudflare One Client (also known as WARP). If you choose to install and use this client to reach the lab, Cloudflare collects certain data needed to enrol your device and route your connection securely. This can include your device identifier and name, the email address you enrol with, your IP address, and connection and diagnostic logs. Cloudflare processes this data on our behalf as part of providing the Zero Trust access network that protects the lab.

Using the native client is entirely optional. You can instead reach the lab through your web browser, which does not require the client. By installing the Cloudflare One Client and connecting to the LabFabric network, you agree to this collection and processing.

We do not use this data for marketing, advertising, or profiling, and we never sell it. It is retained only for as long as necessary to operate and secure your lab session and is deleted as soon as reasonably possible afterwards.

3. How we use your data

  • to create and manage your bookings and grant access to your booked lab sessions;
  • to process payments and issue refunds;
  • to send service communications such as booking confirmations, reminders, cancellations, and replies to your enquiries;
  • to operate, secure, maintain, and improve the Service and prevent abuse;
  • to comply with our legal and accounting obligations.

4. Legal bases

We rely on the following legal bases under the UK GDPR:

  • Contract: to provide the Service you have booked and to process your payments.
  • Legitimate interests: to keep the Service secure, prevent fraud and abuse, and improve our offering, balanced against your rights.
  • Legal obligation: to retain transaction records for tax and accounting purposes.
  • Consent: where you voluntarily submit optional information; you may withdraw consent at any time.

5. Cookies

We use a small number of strictly necessary cookies to keep you signed in to your account and to keep your session secure. We also store your display preferences (such as theme and currency) in your browser. We do not use advertising or third-party tracking cookies. You can clear or block cookies in your browser settings, but the Service may not function correctly without the necessary ones.

6. Sharing your data

We share personal data only with service providers who help us run the Service, including:

  • Stripe: payment processing;
  • Our email provider: to send transactional emails;
  • Cloudflare: to deliver and secure the Service, to control access to lab environments for the duration of your booking, and, if you use the Cloudflare One Client (WARP), to enrol your device and route your lab connection (see section 2).

These providers process data on our behalf under appropriate contracts. We do not sell your personal data. We may disclose data where required by law or to establish, exercise, or defend legal claims.

7. International transfers

Some of our providers may process data outside the UK. Where they do, we rely on appropriate safeguards recognised under the UK GDPR, such as adequacy regulations or the International Data Transfer Agreement (or equivalent standard contractual clauses).

8. Data retention

We keep booking and transaction records for as long as needed to provide the Service and to meet our legal, tax, and accounting obligations (typically up to six years for financial records). Other personal data is kept only as long as necessary for the purposes described above, after which it is deleted or anonymised.

9. Your rights

Under the UK GDPR you have the right to:

  • access a copy of the personal data we hold about you;
  • have inaccurate data corrected;
  • have your data erased in certain circumstances;
  • restrict or object to certain processing;
  • data portability;
  • withdraw consent where processing is based on consent.

To exercise any of these rights, contact us at [email protected]. You also have the right to complain to the UK Information Commissioner’s Office (ICO) at ico.org.uk, though we’d appreciate the chance to address your concerns first.

10. Security

We use appropriate technical and organisational measures to protect personal data, including encryption in transit, access controls, and secure session handling. No method of transmission or storage is completely secure, but we work to protect your data and to respond promptly to any incident.

11. Changes & contact

We may update this policy from time to time; the “Last updated” date above reflects the latest version. For any privacy question or request, contact us at [email protected].