Legal

Privacy policy

What we collect, why we collect it, how long we keep it, and what you can ask us to do with it.

Effective 1 September 2026Algolyzer Lab

1. Who is responsible for your data

Algolyzer Lab (“we”, “us”, “the studio”) is the controller of the personal data described in this policy. We are an applied machine learning and IoT studio: we build measurement and decision systems that, as a rule, run on our clients’ own data and on hardware they control.

Questions about this policy, and any request to exercise the rights set out in section 11, should go to hello@algolyzerlab.com. Our address for correspondence is 20, Power House Main Road, Kawatkhali, 10-A, Noor Garden, Mymensingh, Mymensingh, 2201, Bangladesh. You can also reach us by telephone on +8801933643065. Our full business details are published on our company page.

2. What this policy covers

This policy applies to three separate things, which are worth keeping apart:

  • This website. The public pages, and the contact form on them.
  • The studio’s own admin panel. A private area used by our staff to read enquiries and edit what this site publishes.
  • Engagement work. Pilot and build projects carried out for a client, and the hosted products we operate. Personal data inside a client’s own dataset is governed by section 8 and by the contract for that engagement, not by this section.

3. What we collect

3.1 What you send us through the contact form

The contact form asks for your name, your email address and your message, which are required, and your organisation, your country and the product your enquiry is about, which are optional. Nothing else is requested and nothing else is inferred. The form posts directly to our own server; it is not routed through a third-party form or marketing service.

The record we store consists of exactly those fields, the time we received the enquiry, and the internal handling fields our staff use to work the enquiry: a status, a stage, a priority, an indicative value and the person it is assigned to. We do not record your IP address against the enquiry, and we do not attach a tracking identifier, a browsing history or a marketing profile to it.

3.2 What our servers record automatically

Like any web server, ours writes an operational log line for each request. It contains the request method, the path requested, the response status, how long the request took and the IP address the request came from. These logs exist to keep the service running and secure — diagnosing errors, spotting abuse and investigating a suspected intrusion — and are not used to build a profile of you or to measure you as an audience.

3.3 Staff accounts

People who work at the studio have an account for the admin panel holding their name, work email address, a role and a hashed password. Passwords are stored only as a one-way hash; we cannot read them.

3.4 What we do not collect

We do not collect special category data through this site, we do not buy personal data from data brokers, we do not enrich or append to what you send us from third-party sources, and we do not operate a newsletter or a marketing automation sequence from the contact form.

4. Cookies, local storage and third-party requests

This site sets no advertising cookies and no analytics cookies. There is no tag manager, no advertising pixel and no product-analytics script on any public page. Browsing this site does not place a cookie in your browser.

The site stores one thing on your device: a light or dark theme preference, kept in your browser’s local storage so that the site does not flash the wrong colours on your next visit. It holds only the word “light” or “dark”, it is never sent to our server, and clearing your browser data removes it.

One cookie exists on this domain and it belongs to the admin panel. When a member of our staff signs in, we set a session cookie holding a signed token that identifies their account, their email address and their role. It is marked HttpOnly, so page scripts cannot read it; it is marked Secure in production, so it only travels over an encrypted connection; it expires after a fixed lifetime set by us and is cleared when they sign out. It is a strictly necessary cookie for authentication, and a visitor who never signs in is never given one.

The site’s typefaces are served from this domain. They used to be fetched from Google’s hosted font service, which disclosed your IP address and browser user agent to that service on every page load; they are now downloaded when the site is built and served alongside the pages themselves, so loading this site contacts no third party at all.

5. Why we use your data, and our lawful basis

  • To reply to an enquiry and scope work. We rely on our legitimate interest in responding to a business approach made to us, and on the steps taken at your request before entering a contract. Without your name and email we cannot answer you.
  • To keep a record of a commercial relationship. Legitimate interest in knowing who we have spoken to and what we agreed, and, where invoices exist, compliance with the tax and accounting law that applies to us.
  • To keep the service available and secure. Legitimate interest in the integrity of our own systems, which is what the server logs in section 3.2 are for.
  • To run the studio’s admin panel. Performance of our contract with the member of staff, and our legitimate interest in controlling access to it.
  • To deliver an engagement. Performance of the contract with the client. Where that engagement involves personal data belonging to the client, see section 8.

6. How long we keep it

Enquiries are kept while the conversation is live and, if it turns into work, for as long as we need a record of the relationship and to meet our accounting and tax obligations. Enquiries that go nowhere are deleted once they are of no further use, and we will delete one earlier if you ask us to. Operational server logs are short-lived: they are rotated and discarded by our hosting infrastructure once they are no longer useful for security and troubleshooting. Staff accounts are removed when someone leaves the studio.

7. Who else sees it

We do not sell personal data, and we do not share it for advertising. No data broker, ad network or social platform receives anything from us. The people outside the studio who may process personal data on our behalf are described by role:

  • Hosting and infrastructure. The provider that runs the servers and database this site and its API sit on, which necessarily processes what those systems hold.
  • Email. The provider that carries our correspondence, so that a reply to your enquiry passes through their systems.
  • Professional advisers. Accountants and lawyers, where a specific matter requires it.

We will also disclose data where we are legally required to, and we will tell you about it unless we are prohibited from doing so.

8. On-premise deployment, and client data during an engagement

Our default deployment is on-premise or at the edge: inference runs on the device or on hardware the client controls, so footage, records and sensor data usually never reach the studio at all. This is the single most important thing we do for the privacy of the people in our clients’ datasets, and it is a design decision rather than a policy statement.

Where an engagement does require us to handle personal data belonging to a client, the client is the controller and we act as their processor. We process it only on their documented instructions, for the purposes of that engagement, under the confidentiality and data-protection terms of the contract for it, and we return or delete it at the end of the engagement as that contract requires. We do not use one client’s data to train or improve models for another client, or for ourselves, without their written agreement.

9. Sending data across borders

We work with organisations in more than one country, and our infrastructure may sit in a country other than yours. Where personal data moves across a border, we do so on the basis of the data-protection terms in the relevant contract and the safeguards those terms require. If you would like to know where a specific piece of data is held, ask us and we will tell you.

10. How we protect it

Access to the admin panel requires authentication and an administrator role; passwords are hashed rather than stored; session tokens are signed and expire; the session cookie is HttpOnly and, in production, Secure; the API sends a strict set of security headers and caps the size of any submission it accepts. No system is perfect, and we make no claim beyond describing what we actually do.

11. Your rights

Subject to the law that applies to you, you can ask us to:

  • confirm what personal data we hold about you, and give you a copy of it (access);
  • correct anything inaccurate or incomplete (rectification);
  • delete it (erasure);
  • restrict what we do with it while a question about it is resolved (restriction);
  • provide it in a portable, machine-readable form, or send it to someone else (portability);
  • stop processing that we base on our legitimate interests, including any direct marketing (objection);
  • withdraw a consent you have given, without affecting what we did before you did so.

Email hello@algolyzerlab.com to exercise any of these. We may ask you to reply from the address already in the record, or to confirm a detail only you would know, so that we do not disclose your data to somebody else. We answer without undue delay. If you are unhappy with our answer, you can complain to the data protection supervisory authority in your country; we would rather you told us first, so that we can put it right.

12. Children

This site, and everything we sell, is directed at organisations and the people who work for them. It is not directed at children and we do not knowingly collect the personal data of a child through it. If you believe a child has sent us personal data, write to us and we will delete it.

13. Changes to this policy

When this policy changes, we publish the new version on this page and change the effective date at the top of it. Where a change materially affects how we handle data we already hold about you, we will tell the people affected directly rather than relying on you noticing a new date. Superseded versions are available on request.

14. How to reach us

Write to hello@algolyzerlab.com, telephone +8801933643065, or post to 20, Power House Main Road, Kawatkhali, 10-A, Noor Garden, Mymensingh, Mymensingh, 2201, Bangladesh. You can also use the contact form, though for a privacy request email is faster. This policy should be read with our terms of service and our refund and cancellation policy.