Privacy notice

What we do with your personal data

This covers ligara.org, the website you are reading. The Ligara application has its own notice, published when it opens for sign-up. In practice the only personal data this site collects is what you choose to type into the contact form.

This notice is awaiting legal review. It is published because a site that collects enquiries with no notice at all is worse, and everything in it is accurate to the best of our knowledge. Passages marked as still being settled are marked as such rather than filled with a plausible guess. A reviewed version will replace it.

01 · Who we are

The data controller

Ligara Ltd

A private company limited by shares, registered in England and Wales under the Companies Act 2006.

  • Company number 17462687
  • Registered office Flat 44 Elm Park Mansions, Park Walk, London SW10 0AW, United Kingdom
  • Privacy contact info@ligara.org

TODO(legal): confirm whether a dedicated privacy mailbox is wanted, and whether the ICO data protection fee has been paid — a UK company processing personal data generally must register unless exempt.

Data protection officer

We have not appointed one. A DPO is mandatory only for public authorities, for large-scale monitoring, or for large-scale processing of special-category data, and none of those applies to a company of this size handling business enquiries.

Questions still go to a person, not a form. Write to info@ligara.org and mark it for the attention of the data controller.

02 · What and why

The data, the purpose, and the lawful basis

UK GDPR requires a lawful basis for every purpose, not one basis for the whole organisation. There are two purposes here.

Personal data collected, the purpose, and the lawful basis for each
What we collect Why Lawful basis Retention
Contact form Your name, work email, organisation, role, organisation type, team size, plate readers you use, and the free text you write. Used to answer your enquiry, arrange a demo, and follow up on it. Legitimate interests — Article 6(1)(f). Ours is responding to a business enquiry you chose to send us; the balance favours it because you initiated the contact and would expect a reply. Where the exchange turns into a contract, Article 6(1)(b) also applies. TODO(legal): set this. Proposed — 24 months from last contact, then deletion, so a lapsed enquirer is not held indefinitely.
Request logs Your IP address, browser and operating system, the page requested, and an approximate location derived from the IP. Generated automatically by the infrastructure that serves the site; used to deliver pages, keep the site up, and block abuse. Legitimate interests — Article 6(1)(f), in operating and securing a website. No record is created that identifies you by name, and we do not attempt to link a log entry to a person. Held by Cloudflare under its own retention schedule. TODO(legal): state Cloudflare's period once confirmed.
Traffic measurement A page view each time a page loads, recorded by Cloudflare Web Analytics: the page, the referring site, rough location from your IP address, device type and browser. Used to understand which pages are read and where visitors come from, so we can decide where to put a small marketing budget. Nothing is stored on your device to do this — no cookie, no localStorage — and there is no identifier that would let us recognise you on a later visit or on another site. Legitimate interests — Article 6(1)(f), in understanding whether our own website works. The balance favours it because the measurement is aggregate, stores nothing on your equipment and cannot be used to single you out. Because nothing is stored on or read from your device, PECR regulation 6 does not require consent and we do not ask for it. Cloudflare retains Web Analytics data for a rolling period and we see only the aggregate. TODO(legal): confirm Cloudflare's stated Web Analytics retention period and record it here.
  • No cookies and no browser storage. Verifiable in your own developer tools, and set out on the cookies page.
  • One analytics tool, and it stores nothing on your device. Cloudflare Web Analytics counts page views. There is no advertising or cross-site tracking product on this site, no ad pixel and no remarketing tag. Detailed on the cookies page.
  • No special-category data is sought. Please do not put health, biometric or other sensitive personal data in the message box.
  • No automated decision-making and no profiling. A person reads every enquiry.
  • Not directed at children. This is a business product and we do not knowingly collect data from anyone under 18.
  • Giving us data is optional. You can read the entire site without submitting anything. If you would rather not use the form, email us.
03 · Who else sees it

Recipients and international transfers

We do not sell personal data, we do not share it for advertising, and we do not pass it to anyone for their own purposes. It is handled by the service providers we use to run the site and our email.

Each of them, what it does, and where it does it, is named in full on the subprocessor list — including which steps of the path involve leaving the UK. The short version:

  • Cloudflare serves this site and runs the small program that receives the form.
  • Resend, in the United States, delivers the enquiry to us as an email, through Amazon SES, also in the United States.
  • Microsoft 365, in the United Kingdom, hosts the mailbox where it arrives and where our reply is written.

So a contact-form enquiry transits the United States before coming to rest in a UK mailbox. That is a restricted transfer under UK GDPR Chapter V and needs an appropriate safeguard. If that routing does not suit your organisation, email info@ligara.org directly and the message reaches the UK mailbox without passing through Resend at all.

TODO(legal): record the transfer mechanism relied on for each US recipient — the UK International Data Transfer Agreement, the UK Addendum to the EU Standard Contractual Clauses, or the UK–US Data Bridge where the vendor is certified — together with the date and the transfer risk assessment.

We may also disclose personal data where we are legally required to, or to professional advisers under a duty of confidence, or to a buyer if the business is sold. None of those is routine and none has happened.

04 · Your rights

What you can ask us to do

These are statutory. Exercising one is free, we will not ask you to justify it, and we will respond within one month.

  • Access. Ask what we hold about you and get a copy.
  • Rectification. Have anything inaccurate corrected.
  • Erasure. Have it deleted, where no reason to keep it applies.
  • Restriction. Have us pause processing while a dispute is resolved.
  • Objection. Object to processing based on legitimate interests — which is the basis for everything on this site. Say the word and we stop.
  • Portability. Receive the data you gave us in a machine-readable form.
  • Withdraw consent. Listed for completeness. We do not rely on consent for anything here, so there is nothing to withdraw.
  • Complain. To us, or straight to the regulator.

Asking us

Email info@ligara.org. Tell us which right you are exercising. If we cannot identify you from what you send, we may have to ask for enough detail to be sure — we would rather check than hand your enquiry history to someone else.

One month, from the day we receive it. If a request is genuinely complex we may extend by two further months, and we will tell you why within the first month rather than going quiet.

Complaining to the ICO

You can complain to the Information Commissioner's Office at any time. You do not have to come to us first, though we would rather have the chance to put something right.

05 · Keeping it safe

Security measures

Proportionate to what this site actually holds, which is a mailbox of business enquiries rather than a database of customer records.

  • HTTPS everywhere, with HTTP Strict Transport Security.
  • A Content Security Policy that permits scripts only from this domain, so an injected third-party script does not execute.
  • No database. The contact form is turned into an email and forgotten; nothing about your enquiry is stored by the website itself.
  • Access to the mailbox is limited to the people who need to answer you.

The technical position for the product, including an open register of what is not yet built, is on the security page. Vulnerability reports are welcome — see reporting a vulnerability.

The application is covered separately

Everything above is about this website. The Ligara application holds an entirely different class of data — your compounds, your assay results, your inventory — and is a separate system with its own processors and its own notice.

Where you use Ligara to hold personal data about your own staff or collaborators, you are the controller and we are your processor. That relationship needs a data processing agreement, not a privacy notice.

See the legal status page for where that agreement has got to, and ask us if you need a position in writing before it is finished.

Changes

When this notice changes

We will update this page and change the review date below. If a change materially affects how we handle data we already hold about you, we will tell the people affected rather than relying on you to re-read the page.

TODO(legal): decide whether to keep a dated version history on this page. For procurement reviews it is useful evidence; it also makes every change permanently visible, which is a decision rather than an oversight.

Version 0.1, published 17 September 2026. Awaiting legal review.
See also cookies, subprocessors, terms and legal status.